Grandstream Networks, Inc.

Size: px
Start display at page:

Download "Grandstream Networks, Inc."

Transcription

1 Grandstream Networks, Inc. GWN7000 Enterprise Multi-WAN Gigabit VPN Router User Manual

2 COPYRIGHT 2017 Grandstream Networks, Inc. All rights reserved. Information in this document is subject to change without notice. Reproduction or transmittal of the entire or any part, in any form or by any means, electronic or print, for any purpose without the express written permission of Grandstream Networks, Inc. is not permitted. The latest electronic version of this guide is available for download here: Grandstream is a registered trademark and Grandstream logo is trademark of Grandstream Networks, Inc. in the United States, Europe and other countries. OPEN SOURCE LICENSES GWN7000 firmware contains third-party open source software. Grandstream Open source licenses can be downloaded from Grandstream web site from here CAUTION Changes or modifications to this product not expressly approved by Grandstream, or operation of this product in any way other than as detailed by this guide, could void your manufacturer warranty. WARNING Please do not use a different power adaptor with devices as it may cause damage to the products and void the manufacturer warranty. P a g e 2

3 Table of Contents DOCUMENT PURPOSE CHANGE LOG Firmware Firmware Version Firmware Version Firmware Version WELCOME PRODUCT OVERVIEW Technical Specifications INSTALLATION Equipment Packaging Connect your GWN Safety Compliances Warranty GETTING STARTED LED Indicators Use the WEB GUI Access WEB GUI WEB GUI Languages WEB GUI Configuration Overview Page Save and Apply Changes ROUTER CONFIGURATION Status Ports Configuration WAN Ports Settings Tunnel Global Settings Port Mirroring Static Routes P a g e 3

4 QoS DDNS DPI SETTING UP A WIRELESS NETWORK Discover and Pair GWN76xx Access Points Network Groups Create an SSID under a Network Group Additional SSID under Same Network Group Client Bridge CLIENTS CONFIGURATION Clients Status Edit IP and Name Bandwidth Rules Block a client Clients Access Time Policy Banned Clients VPN (VIRTUAL PRIVATE NETWORK) Overview OpenVPN Server Configuration Generate Self-Issued Certificate Authority (CA) Generate Server/Client Certificates Create OpenVPN Server OpenVPN Client configuration L2TP/IPSEC Configuration GWN7000 L2TP/IPSec Client Configuration PPTP CONFIGURATION GWN7000 Client Configuration GWN7000 PPTP Server Configuration FIREWALL Basic Settings General Settings Port Forwarding DMZ P a g e 4

5 Inter-Group Traffic Forwarding UPnP Traffic Rules Settings Firewall Advanced Settings General Settings SNAT DNAT CAPTIVE PORTAL Policy Configuration Page Files Configuration Page Clients Page BANDWIDTH RULES MAINTENANCE AND TROUBLESHOOTING Maintenance Debug Capture Ping/Traceroute Syslog NAT Table /Notification LED Schedule File Sharing SNMP User Manager UPGRADING AND PROVISIONING Upgrading Firmware Upgrading via WEB GUI Provisioning and backup Download Configuration Configuration Server Reset and reboot EXPERIENCING THE GWN7000 ENTERPRISE ROUTER P a g e 5

6 Table of Tables Table 1: GWN7000 Technical Specifications Table 2: GWN7000 Equipment Packaging Table 3: LED Indicators Table 4: Overview Table 5: GWN7000 WEB GUI Router Port WAN Port (1,2) Table 6: 6In4 Tunnels Table 7: 6rd Tunnels Table 8: AICCU Tunnels Table 9: GWN7000 WEB GUI Router Port Global Settings Table 10: Port Mirroring Table 11: IPv4 Static Routes Table 12: IPv6 Static Routes Table 13: QoS Basic Table 14: Upstream QoS Table 15: QoS Policer Table 16: QoS Smart Queue Table 17: DPI Settings Table 18: Device Configuration Table 19: Basic Table 20: Wi-Fi Table 21: Time Policy Parameters Table 22: CA Certificate Table 23: Server Certificate Table 24: Client Certificate Table 25: OpenVPN Server Table 26: OpenVPN Client Table 27: L2TP Configuration Table 28: PPTP Configuration Table 29: PPTP Server Configuration Parameters Table 30: Port Forward Table 31: DMZ Table 32: UPnP Settings Table 33: Firewall Traffic Rules Table 34: Firewall-General Settings Table 35: SNAT Table 36: DNAT P a g e 6

7 Table 37: Basic Configuration Page Table 38: Bandwidth Rules Table 39: Maintenance Table 40: Debug-Capture Table 41: Setting Table 42: Events Table 43: LED Schedule settings Table 44: Add a New File to Share Table 45: SNMP Basic Page Table 46: SNMP Advanced Page Table 47: VPN User Parameters Table 48: Network Upgrade Configuration P a g e 7

8 Table of Figures Figure 1: GWN7000 Front View Figure 2: GWN7000 Back View Figure 3: GWN7000 Web GUI Login Page Figure 4: Change Password on first boot Figure 5: Setup Wizard Figure 6: GWN7000 Web GUI Language Figure 7: GWN7000 Web GUI Language Figure 8: Overview Page Figure 9: Apply Changes Figure 10: Router's Status Figure 11: QoS Figure 12: DPI Status Figure 13: Discover AP Figure 14: Discovered Devices Figure 15: GWN7610 online Figure 16: locating Access Points Figure 17: Network Group Figure 18: Add a New Network Group Figure 19: Device Membership Figure 20: Wi-Fi Schedule Figure 21: Add AP to Network Group from Access Points Page Figure 22: Create an SSID Figure 23: Additional SSID Figure 24: Additional SSID Created Figure 25: Client Bridge Figure 26: Clients Figure 27: Client's Status Figure 28: Client's Configuration Figure 29: Client Bandwidth Rules Figure 30: Block a Client Figure 31: Unban Client Figure 32: Global Blacklist Figure 33: Managing the Global Blacklist Figure 34: Blacklist Access List Figure 35: Ban/Unban Client Figure 36: Create CA Certificate Figure 37: CA Certificate Figure 38: Generate Server Certificates P a g e 8

9 Figure 39: User Management Figure 40: Client Certificate Figure 41: Create OpenVPN Server Figure 42: OpenVPN Figure 43: OpenVPN Client Figure 44: OpenVPN Client Figure 45: L2TP Client Configuration Figure 46: L2TP Client Figure 47: PPTP Client Configuration Figure 48: PPTP Client Figure 49: PPTP Server Configuration Figure 50: Basic General Settings Figure 51: Port Forward Figure 52: DMZ Figure 53: Inter-group Traffic Forwarding Figure 54: Enabling inter-group traffic Figure 55: Traffic Rules Settings Figure 56: portal_default.html page Figure 57: portal_pass.html page Figure 58: Files Settings Page Figure 59: Client Web Page Figure 60: MAC Address Bandwidth rule Figure 61: Bandwidth Rules Figure 62: Logserver Configuration Figure 63: Capture Files Figure 64: IP Ping Figure 65: Traceroute Figure 66: Syslog Figure 67: NAT table Figure 68: LED Schedule Figure 69: Add a New File to Share Figure 70: File Share Actions Figure 71: Access File Share P a g e 9

10 DOCUMENT PURPOSE This document describes how to configure the GWN7000 to manage wired and wireless networks via an intuitive WebGUI. The intended audiences of this document are network administrators. Please visit to download the latest. This guide covers following topics: Product Overview Installation Getting Started Router Configuration Setting up a Wireless Network Clients Configuration VPN Firewall Captive Portal Bandwidth Rules Maintenance and Troubleshooting Upgrading and Provisioning Experiencing the GWN7000 Enterprise Router P a g e 10

11 CHANGE LOG This section documents significant changes from previous versions of the GWN7000 user manuals. Only major new features or major document updates are listed here. Minor updates for corrections or editing are not documented here. Firmware Added support for enable/disable MPPE in both PPTP server and client. [MPPE] Firmware Version Added support for Additional Routed Subnets. [Additional IPv4 Addresses][Additional IPv4 Static Address][Destination IP] Added support for Timed Client Disconnect and Enhanced Client Blocking. [Clients Access] Added support for Client Bridge (GWN76xx Access Point is required for this feature.). [Client Bridge] Added support for OpenApp ID for Deep Packet Inspection. [DPI] Added support for Syslog Server. [Logserver] Added support for PPTP Server. [PPTP CONFIGURATION] Added support for Smart Queue QoS. [Smart Queue] Added support for Configurable web UI access port.[web WAN Access][Web HTTP Access][Web HTTPS Port] Added support for notifications. [ /Notification] Firmware Version Added support for Captive Portal [CAPTIVE PORTAL] Added support for Bandwidth Rules [BANDWIDTH RULES] Added support for Select Band per SSID [SSID Band] Added support for selectively enable b/g/n [Mode] Added option to enable/disable support for b devices [Allow Legacy Device(802.11b)] Added support for custom wireless power [Custom Wireless Power(dBm)] Added support for AP location using blinking LED [Access Point location] Added support for limit client count per SSID [Wireless Client Limit] Added support for better roaming decision [Enable Voice Enterprise] Added support for LEDs schedule [LED Schedule] Added support for Wi-Fi schedule [Wi-Fi Schedule] Added option to enable/disable DHCP option 66 & 43 override [Allow DHCP options 66 and 43 override] P a g e 11

12 Firmware Version This is the initial version. P a g e 12

13 WELCOME Thank you for purchasing Grandstream GWN7000 Enterprise Multi-WAN Gigabit VPN Router. The GWN7000 is a powerful enterprise-grade multi-wan Gigabit VPN router. Ideal for the enterprise, smallto-medium business, retail, education, hospitality and medical markets, the GWN7000 supports comprehensive Wi-Fi and VPN solutions that can be shared across one or many different physical locations. It features high-performance routing and switching power and a hardware-accelerated VPN client/server for secure inter-office connectivity. To maximize network reliability, the GWN7000 supports traffic load balancing and failover. The GWN7000 features an integrated controller and automated provisioning master that can setup and manage up to 300+ in-network GWN series Wi-Fi Access Points. This can be easily operated through the product s intuitive web browser user interface, which also offers a central panel to monitor and control the entire network Caution: Changes or modifications to this product not expressly approved by Grandstream, or operation of this product in any way other than as detailed by this User Manual, could void your manufacturer warranty. Warning: Please do not use a different power adaptor with the GWN7000 as it may cause damage to the products and void the manufacturer warranty P a g e 13

14 PRODUCT OVERVIEW Technical Specifications Table 1: GWN7000 Technical Specifications 2 x autosensing 10/100/1000 WAN Ports Network Interfaces 1 x autosensing 10/100/1000 configurable as LAN, WAN or VoIP port 4 x autosensing 10/100/1000 LAN Ports DHCP Static IP WAN PPPoE Load balance & failover Rule based routing DHCP server DNS Cache LAN Multiple zones VLAN 2 x USB 3.0 ports Auxiliary Ports 1 x Reset Pinhole Routing Performance Up to 1 million packets/second with 64-byte packet size Printer sharing USB File sharing Network Protocols IPv4, IPv6, 802.1Q, 802.1p VPN LED Mounting QoS Firewall Auto Provisioning Capability Management Power Protocols: PPTP, L2TP/IPSec, OpenVPN Client, Server or pass through 8 green-color LEDs for device tracking and status indication Indoor wall mount, Desktop VLAN, TOS, supports multiple traffic classes, filter by port, IP address, DSCP, and policing NAT, DMZ, Port Forwarding, SPI, UPnP Embedded provisioning controller to manage up to 300+ GWN series Wi-Fi APs Web, CLI 802.3at PoE Included Power Supply: 12V/2A Max power consumption: 16W P a g e 14

15 Environmental Physical Package Content Compliance Operation: 0 C to 50 C Storage: -10 C to 60 C Humidity: 10% to 90% Non-condensing Unit Dimensions: 200 x 136 x 37mm; Unit Weight: 570g Entire Package Dimensions: 324 x x 54mm; Entire Package Weight: 930g GWN7000 Enterprise Router 12V/2A Power Adapter Quick Installation Guide GPL License FCC, CE, RCM, IC P a g e 15

16 INSTALLATION Before deploying and configuring the GWN7000, the device needs to be properly powered up and connected to the network. This section describes detailed information on installation, connection and warranty policy of the GWN7000. Equipment Packaging Table 2: GWN7000 Equipment Packaging Main Case Yes (1) Power adaptor Yes (1) Quick Installation Guide Yes (1) GPL License Yes (1) Connect your GWN7000 Figure 1: GWN7000 Front View P a g e 16

17 Figure 2: GWN7000 Back View To set up the GWN7000, follow the steps below: 1. Connect one end of an RJ-45 Ethernet cable into the WAN1 or/and WAN2 port(s) of the GWN Connect the other end of the Ethernet cable(s) into a DSL modem or router(s). 3. Connect the 12V DC power adapter into the power jack on the back of the GWN7000. Insert the main plug of the power adapter into a surge-protected power outlet. 4. Wait for the GWN7000 to boot up and connect to internet/network. In the front of the GWN7000 the Power LED will be in solid green, and the WAN LED will flash in green. 5. Connect one of the LAN ports to your computer, the associated LED ports will flash in green. 6. (Optional) Connect LAN ports to your GWN76xx access points or/and other devices, the associated LED ports will flash in green. Safety Compliances The GWN7000 Enterprise Router complies with FCC/CE and various safety standards. The GWN7000 power adapter is compliant with the UL standard. Use the universal power adapter provided with the GWN7000 package only. The manufacturer s warranty does not cover damages to the device caused by unsupported power adapters. Warranty If the GWN7000 Enterprise Router was purchased from a reseller, please contact the company where the device was purchased for replacement, repair or refund. If the device was purchased directly from Grandstream, contact our Technical Support Team for a RMA (Return Materials Authorization) number before the product is returned. Grandstream reserves the right to remedy warranty policy without prior notification. P a g e 17

18 GETTING STARTED The GWN7000 Enterprise Router provides an intuitive web GUI configuration interface for easy management to give users access to all the configurations and options for the GWN7000 s setup. This section provides step-by-step instructions on how to read LED indicators and use Web GUI interface of the GWN7000. LED Indicators The front panel of the GWN7000 has LED indicators for power and interfaces activities, the table below describes the LED indicators status. Table 3: LED Indicators LED Status Indication POWER WAN (1,2) LAN (1,2,3,4,5) OFF Solid green Flashing green Solid green Flashing green Solid green GWN7000 is powered off or abnormal power supply. GWN7000 is powered on correctly. GWN7000 is connected as a client to another network and data is transferring. GWN7000 is connected as a client to another network and there is no activity. A device is connected to the corresponding LAN port and data is transferring. A device is connected to the corresponding LAN port and there is no activity. Use the WEB GUI Access WEB GUI The GWN7000 embedded Web server responds to HTTPS GET/POST requests. Embedded HTML pages allow users to configure the device through a Web browser such as Microsoft IE, Mozilla Firefox, Google Chrome. P a g e 18

19 Figure 3: GWN7000 Web GUI Login Page To access the Web GUI: 1. Connect a computer to a LAN Port of the GWN Ensure the device is properly powered up, and the Power, LAN port LEDs light up in green. 3. Open a Web browser on the computer and enter the web GUI URL in the following format: (Default IP address). 4. Enter the administrator s login and password to access the Web Configuration Menu. The default administrator's username and password are "admin" and "admin". Note: At first boot or after factory reset, users will be asked to change the default administrator and user passwords before accessing GWN7000 web interface. The password field is case sensitive with a maximum length of 32 characters. Using strong password including letters, digits and special characters is recommended for security purposes. P a g e 19

20 Figure 4: Change Password on first boot At first login, a Setup Wizard tool will pop up to help going through the configuration setup, or exit to configure manually. Setup Wizard can be accessed anytime by clicking on while on the web interface. Figure 5: Setup Wizard WEB GUI Languages Currently the GWN7000 series web GUI supports English and Simplified Chinese. To change default language, select the displayed language at the upper right of the web GUI either before or after logging in. P a g e 20

21 Figure 6: GWN7000 Web GUI Language Figure 7: GWN7000 Web GUI Language WEB GUI Configuration GWN7000 web GUI includes 8 main sections to configure and manage the router and check connection status. Overview: Provides an overall view of the GWN7000 s information presented in a Dashboard style for easy monitoring. Router: Displays device s status and used to configure ports settings such as IP configuration for WAN ports, load balancing, failover, static routes, port mirroring, QoS and DDNS. Access Points: To add, pair and manage discovered access points. Clients: Shows and manages the list of the clients connected to LAN ports of the GWN7000 and wireless clients connected via GWN76xx access points. VPN: Configures OpenVPN Client/Server, PPTP and L2TP/IPSec client tunnels. Firewall: Basic and advanced Firewall configuration to securely manage router s incoming/outgoing traffic. Captive Portal: Configuration settings for the captive portal feature. Bandwidth Rules: Configures the bandwidths rules that allows users to limit bandwidth utilization per SSID or client (MAC address or IP address). P a g e 21

22 Network Group: To add and manage wireless network groups using paired access points via VLANs. System Settings: For Maintenance and debugging features, as well as generating certificates and file sharing. Overview Page Overview is the first page shown after successful login to the GWN7000 s Web Interface. It provides an overall view of the GWN7000 s information presented in a Dashboard style for easy monitoring. Figure 8: Overview Page It is used to show the status of the GWN7000 for different items, please refer to the following table for each item: Table 4: Overview Shows the number of Access Points that are Discovered, Paired (Online) AP and Offline. Click on advanced configuration options for the APs to go to Access Points page for basic and Shows the total number of connected clients, and a count for clients Clients connected to each Channel. Click on more options. to go to Clients page for P a g e 22

23 AP Channel Distribution Shows the Channel used for all APs that are paired with this Access Point. Shows the Top APs list, assort the list by number of clients connected to Top AP Top SSID Top Clients Traffic each AP or data usage combining upload and download. Click on to go to Access Points page for basic and advanced configuration options for the APs. Shows the Top SSIDs list, assort the list by number of clients connected to each SSID or data usage combining upload and download. Click on to go to Network Group page for more options. Shows the Top Clients list, assort the list of clients by their upload or download. Click on to go to Clients page for more options. Shows the sent/received traffic data speeds on both WAN ports. Note that Overview page in addition to other tabs can be updated each 15s, 1min, 2min, 5min or Never by clicking in the upper bar menu (Default is 15s). Save and Apply Changes When clicking on "Save" button after configuring or changing any option on the web GUI pages. A message mentioning the number of changes will appear on the upper menu. Figure 9: Apply Changes Click on button to apply changes, or to undo the changes. P a g e 23

24 ROUTER CONFIGURATION This section includes configuration pages for network WAN ports, static routes, QoS and DDNS and shows also the router status. Status Status page displays Device Status to check MAC address, Part Number, Firmware related information and Uptime for the GWN7000; and WAN Status showing general information about WAN Ports such as uptime, current throughput, aggregate usage, and IP address and also the application traffic. Router s Status page can be accessed from Web GUI Router Status. Figure 10: Router's Status Note: Once DPI is enabled under Router feature. Users will be able to see their application traffics under Application Traffic section Ports Configuration Connect to GWN7000 s Web GUI from a computer connected to a LAN port and go to Router Port page for Port configuration. P a g e 24

25 WAN Ports Settings The GWN7000 has 2 WAN ports configured as DHCP clients by default. Each port can be connected with DSL modem or routers. WAN ports support also setting static IPv4/IPv6 addresses, and configure PPPoE for each WAN port. Please refer to the following table for basic network configuration parameters on WAN ports for GWN7000. Table 5: GWN7000 WEB GUI Router Port WAN Port (1,2) Enabled Name WAN Address Type Preferred IPv4 DNS Alternate IPv4 DNS Native IPv6 IPv6 Address Assignment Choose whether to enable or disable the WAN port. Specify the port name. Select "DHCP", "Static" or "PPPoE" mode on the WAN interfaces of GWN7000. The default setting is "DHCP". DHCP When selected, it will act as a DHCP client and acquire an IPv4 address automatically from the DHCP server. Static When selected, the user should set a static IPv4 address, IPv4 Subnet Mask, IPv4 Gateway and adding Additional IPv4 Addresses as well to communicate with the web interface, SSH, or other services running on the device. PPPoE When selected, the user should set the PPPoE account and password, PPPoE Keep alive interval and Inter-Key Timeout (in seconds). Enter the preferred DNS server address (IPv4 address). If Preferred DNS is set, GWN7000 will use it in priority. Enter the Alternate DNS server address (IPv4 address). If Preferred DNS is set, GWN7000 will use it in when the Preferred DNS fails. Used to enable assigning IPv6 address to GWN7000. Once checked users will be able to configure following fields: IPv6 Address Assignment, Preferred IPv6 DNS, Alternate IPv6 DNS and IPv6 Relay to LAN. This option is appearing when enabling Native IPv6 option. Select "Auto" to get an IPv6 address from DHCP server or "Static" to configure manually an IPv6 address. If set to Static, the following fields should be configured: IPv6 Address/Prefix Length Used to set an IPv6 address/prefix length when using Static IPv6 option Example: fec0:470:28:5b2::1/64 IPv6 Gateway Used to define the Gateway s IPv6 address. IPv6 Prefix/IPv6 Prefix Length Enter the IPv6 prefix and IPv6 prefix length. Example: ::1/64 P a g e 25

26 Preferred IPv6 DNS Alternate IPv6 DNS IPv6 Relay to LAN Multi-WAN VLAN Tagging This option appears only when Native IPv6 option is enabled. It is used to set a preferred DNS server address (IPv6 address). If Preferred DNS is set, GWN7000 will use it in priority. This option appears only when Native IPv6 option is enabled. It is used to set an Alternate DNS server address (IPv6 address). If Preferred DNS is set, GWN7000 will use it in when the Preferred DNS fails. This option appears only when Native IPv6 option is enabled. When enabled the GWN7000 will relay IPv6 address to LAN clients These options are used when both WAN ports are enabled and using Failover feature: Tracking IP Configures the tracking IP(s). ICMP packets are being used to track the IP(s) address(es). When the tracking fails, the GWN7000 will use the secondary WAN port as failover. Default IP used is Tracking Timeout (sec) Configures tracking timeout in seconds. Default value is 2. Tracking Interval (sec) Configures the track interval in seconds. Default value is 5. Bandwidth Specifies the bandwidth for the port, e.g: 100k, 1M or 100M. Used to enable VLAN tagging. If set to 0 the VLAN tagging will be disabled, otherwise set a VLAN value between 5 and Default is 0. Tunnel Tunnel page is used to set IPv6 tunnels on WAN ports via IPv6 tunnel brokers service providers, this serves the purpose of transferring IPv6 packets over IPv4 Network. It supports creating 6in4, 6rd and AICCU tunnels. Please refer to below tables for each tunnel type. Table 6: 6In4 Tunnels WAN Interface MTU 6in4 IPv4 Peer Address 6in4 Tunnel Endpoint IPv6 Address 6in4 Routed Prefix Tunnel ID Username Choose the WAN port on which to setup the 6in4 tunnel. Set the Maximum Transmission Unit value. The valid range is Default value is Enter the IPv4 tunnel endpoint at the tunnel s provider. Enter the local IPv6 address delegated to the tunnel endpoint. Example: 2001:db8:2222::2/64 Set the routable prefix given by the tunnel provider to allow LAN clients to get addresses from that prefix. Specifies the tunnel s ID. Set the username used to login into the tunnel broker. P a g e 26

27 Password Update Key Set the password (used for endpoint update). Set the update key, it overrides the password used for endpoint update. Table 7: 6rd Tunnels WAN Interface MTU 6rd IPv4 Peer Address 6rd IPv6 Address Prefix IPv6 Prefix Length IPv4 Prefix Length Choose the WAN port on which to setup the 6rd tunnel. Set the Maximum Transmission Unit value. The valid range is and default value is Enter the IPv4 Peer address. Specifies the IPv6 prefix given by the provider. Example: 2001:B000::/32 Specifies the IPv6 prefix length (Value between 1 and 128). Example: 32 Specifies the prefix length of the IPv4 transport address. (Value between 1 and 32). Table 8: AICCU Tunnels WAN Interface Username Password Choose the WAN port on which to setup the aiccu tunnel. Enter the Username (Provided by signing up with SixXS Tunnel Broker) Enter the Username s password Global Settings This section specifies operating mode for multi-wan that will be used for enabling/disabling Failover and Load Balancing on WAN ports, and banning MAC addresses. The following table shows the configuration parameters for Multi-WAN settings Table 9: GWN7000 WEB GUI Router Port Global Settings Multi-WAN Disabled Failover Specifies the operating mode for multi -WAN. Three options are available: Disabled Failover: Automatically switch to the connected WAN after failure. Load Balance + Failover: Operating the load balance mode, at the same time automatically switch to the connected WAN after failure. This will disable Multi-WAN feature If chosen failover will be enabled on WAN ports, admins need to choose the Primary WAN port to be used. When selected, user can set Multi-WAN parameters on WAN ports. P a g e 27

28 Load Balance + Failover Banned Client MAC In addition to failover, load balance will be used on both ports to optimize the resource utilization. Please note that for this feature to work, WAN ports should be connected to different networks. When selected, user can set Multi-WAN parameters on WAN ports. Shows the list of banned clients MAC addresses, other MAC addresses could be also added by clicking on or removed by clicking on. Port Mirroring With port mirroring enabled, the GWN7000 will send a copy of all network packets seen on one LAN port to another port, where the packet can be analyzed. Refer to the below table for the available fields to configure. Table 10: Port Mirroring Enable Outgoing Check to enable outgoing mirroring for a LAN port. Default is Disabled Mirroring Enable Incoming Check to enable incoming mirroring for a LAN port. Default is Disabled Mirroring Mirroring Port Select which LAN port that will be mirroring traffic. Default is Disabled Mirrored Port Select which LAN port that will act as mirrored port. Default is Disabled Static Routes GWN7000 supports setting manually static IPv4 and IPv6 routes as well as displaying routing table entries. Static routes configuration page can be accessed from GWN7000 WebGUI Router Static Routes: Three tabs are available: - Routes to view routing table entries. - IPv4 to create, edit or delete static IPv4 static routes. - IPv6 to create, edit or delete static IPv6 static routes. Following actions are available in both IPv4 and IPv6 tabs: To add a new static route, click on To edit a static route, click on To delete a static route, click on Refer to the following tables when editing or creating IPv4/IPv6 static routes: P a g e 28

29 Table 11: IPv4 Static Routes Name Enter the Name of the static route to be configured. Enabled Select whether to enable or disable this static route. Group Choose the LAN s Network Group, which will be using this static route. Target Network/Host Enter the Network/Host IP address on which to route the traffic to. Example: Netmask Enter the Network/Host Netmask. Example: NextHop Enter the NextHop IP address. Example: Metric Set the metric value. The valid range is Default value is 1. Table 12: IPv6 Static Routes Name Enter the Name of the static route to be configured. Enable Select whether to enable or disable this static route. Group Choose the LAN s Network Group Target Network/Host Enter the Network/Host IP address on which to route the traffic to. 2001:db8:3c4d:4::/64 NextHop Enter the Gateway s IP address. fec0:470:28:5b2::1/64 Metric Set the metric value. The valid range is Default value is 1. QoS The GWN7000 offers the possibility to enable and configure QoS on both WAN and LAN interfaces, this will help to manage in more depth the network traffic to define priority and classify different services and protocols in a scheduled manner. Figure 11: QoS P a g e 29

30 To activate QoS, check Enable QoS. Three tabs are available for configuration: Basic: Download and upload bandwidth speeds settings on each WAN interface. Upstream QoS: Upstream QoS allows creating Traffic Classes to prioritize traffic for specific resources on the network by controlling transmission/upload rate. Note that different classes can be created and assigned as Traffic filters by respecting following conditions: The total of Upstream bandwidth values of each created class should not exceed the upstream bandwidth value configured in Basic. The remaining bandwidth will be lent to the next priority level of class. All filter options are summed together. Policer: While Upstream QoS is dealing with traffic transmission, Policer is controlling the incoming traffic. Thus, allowing to create rules to specific targets to set priority and received traffic rate, giving the GWN7000 the ability to drop the exceeding traffic when reaching the configured maximum rate. Smart Queue: The smart queue is an integrated network system that performs better per-packet/per flow network scheduling, reduces the buffer bloat and keeps latency at acceptable levels. Refer to the following tables for each tab option: Table 13: QoS Basic Enabled Upstream Downstream Check to enable upstream and downstream bandwidth speeds for the selected WAN interface. Set the Upstream value to specify the upload bandwidth for selected interface, the value should end with Mbit, Kbit or with no unit if the set value is referring to bit unit. Note that the set value will affect and limit the bandwidth values on created classes on QoS Upstream. Examples: 500Mbit 100Kbit 500 Set the Downstream value to specify the download bandwidth speed for selected interface, the value should end with Mbit, Kbit or with no unit if the set value is referring to bit unit. Examples: 1000Mbit 100Kbit 500 Table 14: Upstream QoS Traffic Class Name Priority Define a name for the traffic class. Set the priority of the traffic class, the lower the value, the highest the priority. Valid range is between 1 and 64. P a g e 30

31 Interface Upstream Class Name DSCP IP Source Address IP Destination Address TCP Source Port TCP Destination Port UDP Source Port UDP Destination Port Group Source Select the WAN interface from which the traffic will be classified, make sure to enable the desired interface it from QoS Basic in order to appear. Set Upstream bandwidth value. The value should end with Mbit, Kbit or with no unit if the set value is referring to bit unit. Note that the sum of created classes should have upstream bandwidth speeds lower than the Upstream bandwidth value configured on QoS Basic. Examples: 100Mbit 100Kbit 500 Traffic Filter Select a class from created traffic classes using drop-down menu. Define a Name for the traffic filter rule. Choose the Differentiated Services Code Point (DSCP) value from drop-down list. Default is 0. Specify the Source IP address from which the traffic filter rule will be applied. Specify the Destination IP address to which the traffic filter rule will be applied. Specify the TCP Source port from which the traffic filter rule will be applied. Specify the TCP Source port to which the traffic filter rule will be applied. Specify the UDP Source port from which the traffic filter rule will be applied. Specify the UDP Source port to which the traffic filter rule will be applied. Choose the LAN group of the specified Source IP address. If no Source IP address has been defined, the rule will be applied to all members of that LAN group. Table 15: QoS Policer Name Interface Priority Rate DSCP IP Source Address IP Destination Address TCP Source Port TCP Destination Port Define a Name for the Policer rule. Select an interface from which the traffic will be policed, make sure to enable the desired interface it from QoS Basic in order to appear. Set the priority of the traffic class, the lower the value, the highest the priority. Valid range is between 1 and 64. Set a Rate value for download bandwidth when applying policer rule. Choose the Differentiated Services Code Point (DSCP) value from drop-down list. Default is 0. Specify the Source IP address from which the policer rule will be applied. Specify the Destination IP address to which the policer rule will be applied. Specify the TCP Source port from which the policer rule will be applied. Specify the TCP Source port to which the policer rule will be applied. P a g e 31

32 UDP Source Port UDP Destination Port Group Source Specify the UDP Source port from which the policer rule will be applied. Specify the UDP Source port to which the policer rule will be applied. Choose the LAN group of the specified Source IP address. If no Source IP address has been defined, the rule will be applied to all members of that LAN group. Table 16: QoS Smart Queue Enabled Qdisc Manager Link -layer Adaptation Overhead Advanced Qdisc Options Squash DSCP on ingress Check this option in order to enable the feature on the WAN interface. Select which Queuing discipline method to use for QoS: fq_codel (Fair Queue with Controlled Delay) Cake Choose the type of the smart queue management: If fq_codel queuing discipline method is selected. simple: Three-tier prioritization system. simplest: HTB (Hierarchical Token Bucket) shaper with a single fq_codel queuing discipline. simplest_tbf: TBF (Token Bucket Filter) shaper with a single fq_codel queuing discipline. If cake queuing discipline method is selected. layer_cake: Three-tier prioritization system with cake as a replacement for HTB rate limiting. piece_of_cake: Single queue with cake as a replacement for HTB rate limiting. Select the link-layer type for the WAN connection. This can be used to compensate for the link-layer overhead of certain types of WAN connections. None (default). Ethernet (should be selected for VDSL connections). ATM (should be selected for ADSL connections). If the link-layer is set to something other than none, then the link-layer overhead setting can be used to specify how many bytes of overhead there are. Defaults are 8 for Ethernet, and 44 for ATM. Check this option in order to show advanced Qdisc options to be used. Select whether to squash or not the DSCP on ingress packets. By default, this option is disabled. P a g e 32

33 Ignore DSCP on ingress ECN Status on Inbound packets Select whether to ignore DSCP on ingress packets or not. By default, this option is disabled. Select whether to set or not ECN status on inbound packets. DDNS DDNS allows accessing GWN7000 via domain name instead of IP address, the GWN7000 supports following DDNS providers: Dyndns.org Changeip.com Zoneedit.com Free.editdns.net Freedns.afraid.org He.Net Dnsomatic.Com No-ip.pl Myonlineportal.net Before configuring DDNS settings on the GWN7000, make sure first to create and confirm the DDNS account via supported providers. Following steps illustrates how to configure the DDNS settings on your GWN7000: 1. Access to GWN7000 web GUI, and navigate to Router DDNS, and enable DDNS service. 2. Fill in the domain name created with DDNS provider under Domain Name field. 3. Enter your account username and password under Username and Password fields. 4. Specify the WAN interface to which DDNS is applied under Network interface field. 5. (Optional) For advanced configuration, it is also possible log to Syslog and modify the values of refreshing fields so to check periodically the updated IP address. DPI DPI stands for Deep Packet Inspection which is an option that allows the GWN7000 to analyze the core of the packet to collect and report information at the Application-layer, such as traffic volume of an application used by the host. Snort OpenApp ID allows the System Administrator to view the internet traffic of users. The GUI displays traffic data in a human-readable format, such as 'Streaming MP4 & Netflix - 31% of total traffic usage.' The data is accompanied by a graph. P a g e 33

34 GWN7000 is using Snort for packet inspection and displays traffic status under Status Application Traffic as shown on the figure below. Figure 12: DPI Status The following table contains the description of the DPI configuration settings. Table 17: DPI Settings Enable Application Tracking Interface Enables the application tracking. By default, it s disabled. Select the interface on which the application tracking will be performed. By default, it s WAN Port 1. Note: A reboot is required after enabling Depp packet inspection in order for the feature to take effect. P a g e 34

35 SETTING UP A WIRELESS NETWORK The GWN7000 Enterprise Router provides the user with the capability to create a wireless network by adding multiple GWN76xx series access points, with connectivity over the most common wireless standards (802.11b/g/n) operating in both 2.4GHz and 5GHz range. The GWN7000 integrates multiple layers of security including the IEEE 802.1x port-based authentication protocol, Wired Equivalent Privacy (WEP), Wi-Fi Protected Access (WPA and WPA2) and firewall and VPN tunnels. This chapter will introduce how to discover, add the GWN76xx access points, create and manage Wi-Fi Networks. For more details about Grandstream GWN76xx Access points, refer to Discover and Pair GWN76xx Access Points The GWN76xx are powerful access points, which are fully compatible with the GWN7000 and can be added with one click, provisioned and managed in an easy and intuitive way. Once a GWN76xx is successfully connected and has an IP from the GWN7000 router, user can then pair it to the GWN7000 and associate it with a Network Group. To Pair a GWN76xx access point connected as LAN client to the GWN7000, follow the below steps: 1. Connect to the GWN7000 Web GUI and go to Access Points. Figure 13: Discover AP 2. Click on to discover access points within GWN7000 s LAN Network, the following page will appear. P a g e 35

36 Figure 14: Discovered Devices 3. Click on Pair under Actions, to pair the discovered Access Point with the GWN The paired GWN76xx will appear Online, Click on to unpair it. Figure 15: GWN7610 online 5. Click on next to paired access point to check device configuration for its status, users connected to it and configuration, or select multiple GWN76xx APs from the same model, and click on to apply same configuration on selected units. 6. Click on to configure client bridge on the selected access point. For more details about the client bridge feature, please refer to Client Bridge. Refer to below table for Device Configuration tabs. Table 18: Device Configuration Status Clients Configuration Shows the device s status information such as Firmware version, IP Address, Link Speed, Uptime, and Users count via different Radio channels. Shows the Clients connected to the GWN76xx access point. Device Name: Set GWN76xx s name to identify it along with its MAC address. P a g e 36

37 Fixed IP: Used to set a static IP for the GWN76xx, if checked, the following needs to be configured: -IPv4 Address: Enter the IPv4 address to be set as static for the device -IPv4 Subnet Mask: Enter the Subnet Mask. -IPv4 Gateway: Enter the Network Gateway s IPv4 Address. -Preferred IPv4 DNS: Enter the Primary IPv4 DNS. -Alternate IPv4 DNS: Enter the Alternate IPv4 DNS. Frequency: Set the GWN76xx s frequency, it can be either 2.4GHz, 5GHz or Dual-band. Enable Band Steering: When Frequency is set to Dual-Band, check this option to enable Band Steering on the Access Point, this will help redirecting clients to a radio band accordingly for efficient use and to benefit from the maximum throughput supported by the client. Mode: Choose the mode for the frequency band, n/g/b for 2.4Ghz and ac for 5Ghz. Channel Width: Choose the Channel Width, note that wide channel will give better speed/throughput, and narrow channel will have less interference. 20Mhz is suggested in very highdensity environment. 40MHz Channel Location: Configure the 40MHz channel location when using 20MHz/40MHz in Channel Width, it can be set it to be Secondary Below Primary, Primary Below Secondary or Auto. Channel: Select Auto or a specific channel. Default is Auto. Note that the proposed channels depend on Country Settings under System Settings >Maintenance. Enable Short Guard Interval: Check to activate this option to half the guard interval (from 800ns to 400ns) ensuring that distinct transmissions do not interfere with one another, this will help increasing throughput. Active Spatial Streams: Choose active spatial stream. Available options: Auto, 1 stream, 2 streams and 3 streams (For GWN7610). P a g e 37

38 Radio Power: Set the Radio Power depending on desired cell size to be broadcasted, three options are available: Low, Medium or High. Default is High. Allow Legacy Device(802.11b): This feature appears when Mode option is set to g or n, it allows legacy devices not supporting g/n mode to connect using the b mode. Custom Wireless Power(dBm): allows users to set a custom wireless power for both 5GHz/2.4GHz band, the value of this field must be between 1 and 31. Access Point location GWN7000 router has an interesting feature to help users to locate different access points using blinking LED, to do so go under the access points page then click on button as shown on the below figure and the corresponding LED will start blinking its LEDs. This can help ease locating the Access points on a multideployment site. Figure 16: locating Access Points Note: If a GWN76xx is not being paired, or the pair icon is grey color, make sure that it is not being paired with another GWN7000 Router or GWN76xx Access Point acting as Master Controller, if yes, it needs to be unpaired first, or reset to factory default settings to make it available for pairing. Network Groups GWN7000 supports creating up to 16 different Network groups separated by VLANs and adding paired GWN76xx Access Points. To access Network Groups configuration page, log in to the GWN7000 WebGUI and go to Network Group Network Group. P a g e 38

39 Figure 17: Network Group The GWN7000 will have a default network group named group0, click on Add to add a new network group. to edit it, or click on Figure 18: Add a New Network Group When editing or adding a new network group, following tabs will appear to configure a network group: P a g e 39

40 Basic: Used to name the network group, and set a VLAN ID if adding a new network group, and addressing plans, refer to below table for each field. Table 19: Basic Network Group Name Enabled WAN Membership LAN Membership VLAN Specifies the name for the network group. Check to activate the newly created network group. Select the WAN port membership. Or use Multi-WAN option if enabled under Router Port Global Settings Select the LAN port membership. Check to enable VLAN. This field is appearing only when having more than a network group. VLAN ID Set a VLAN ID. Valid range is between 2 and Enable IPv4 IPv4 Static Address Additional IPv4 Static Address IPv4 Subnet Mask DHCP Enabled for IPv4 DHCP Start Address DHCP End Address DHCP Lease Time DHCP Options DHCP Gateway DHCP Preferred DNS DHCP Alternate DNS Check to enable IPv4 addressing for this network group Set a static IPv4 address for the network group when enabling IPv4. Set an additional static IPv4 address for the network group when enabling IPv4. Set the Subnet Mask. Check to enable DHCP using IPv4. This will allow clients connected to this network group to get IPv4 addresses automatically from GWN7000 acting as DHCP server. Set the starting IPv4 address for this network group s clients. Set the ending IPv4 address for this network group s clients Set the lease time for DHCP clients, the value can be defined in hours, minutes, or as infinite. Default lease time is 12h. Set the DHCP options. Click on to add another option, and to delete an option. Example: 44, for DHCP option 44 and is the WINS server s address. Please refer to the following link for DHCP options syntax: Defines the IP address of the DHCP gateway. Set the preferred DNS Servers via DHCP. Set the alternate DNS Servers via DHCP. Enable this option, if you want the GWN7000 relays the DHCP requests DHCPv4 Relay Enabled from clients to another DHCP server(s). Once checked Click on to add another DHCPv4 Relay Target, and to delete a DHCPv4 Relay Target. P a g e 40

41 Enable IPv6 IPv6 Relay from WAN DHCP Enabled for IPv6 IPv6 Prefix for Assignment IPv6 Subnet Hint IPv6 Uplink Enable Landing Page Landing Page URL Check to enable IPv6 addressing for this network group. Check to allow GWN7000 to relay IPv6 DHCP request from network group s clients to WAN port. Check weather to enable IPv6 DHCP server for this network group. Set the prefix value to be assigned to the network group. Valid range is between 1 to 64. Example: 64 will assign /64 prefixes. Set the subnet mask value. Select the WAN port. Check to enable landing page when connecting to this network group s Wi-Fi. This will allow setting a landing page URL where wireless users will be redirected automatically to the configured URL. Set the landing page URL to which clients will be redirected once connected to the network group s Wi-Fi. Wi-Fi: Please refer to the below table for Wi-Fi tab options Table 20: Wi-Fi Enable Wi-Fi SSID SSID Band SSID Hidden Wireless Client Limit Enable Captive Portal Captive Portal Policy Check to enable Wi-Fi for the network group. Set or modify the SSID name. Select the Wi-Fi band the GWN will use, three options are available: Dual-Band 2.4GHz 5Ghz Select to hide SSID. SSID will not be visible when scanning for Wi-Fi, to connect a device to hidden SSID, potential wireless clients will need to specify SSID name and authentication password manually. Configure the limit for wireless client. If there s an SSID per-radio on a network group, each SSID will have the same limit. Setting a limit of 50 will limit each SSID to 50 users independently. If set to 0 the limit is disabled. Click on the checkbox to enable the captive portal feature. Select the captive portal policy already created on the Captive portal web page to be used in the created SSID. Set the security mode for encryption. 5 options are available: Security Mode WEP 64-bit: Using a static WEP key. The characters can only be 0-9 or A-F with a length of 10, or printable ASCII characters with a length of 5. P a g e 41

42 WEP 128-bit: Using a static WEP key. The characters can only be 0-9 or A-F with a length of 26, or printable ASCII characters with a length of 13. WPA/WPA2: Using PSK or 802.1x as WPA Key Mode, with AES or AES/TKIP Encryption Type. WPA2: Using PSK or 802.1x as WPA Key Mode, with AES or AES/TKIP Encryption Type. Recommended configuration for authentication. Open: No password is required. Users will be connected without authentication. Not recommended for security reasons. Client Bridge Support Client Time Policy Use MAC Filtering Configures the client bridge support to allows the access point to be configured as a client for bridging wired only clients wirelessly to the network. When an access point is configured in this way, it will share the WiFi connection to the LAN ports transparently. Once a Network Group has an Client Bridge Support enabled, the AP adopted in this Network Group can be turned in to Bridge Client mode by click the Bridge button. Configures the client time policy. Default is None. Choose Blacklist/Whitelist to specify MAC addresses to be excluded/included from connecting to the zone s Wi-Fi. Default is Disabled. Client isolation feature blocks any connection between Wireless clients connected to GWN76xx s Wi-Fi access point. Client isolation can be helpful to increase security for Guest networks/public WiFi. Available modes are: Internet Mode: Wireless clients will be allowed to access only the internet services and they cannot access any of the management services, either on the router nor the GWN76xx access points. Client Isolation Gateway MAC Mode: Wireless clients can only communicate with the gateway, the communication between Wireless clients is blocked and they cannot access any of the management services on the GWN76xx access points. Radio Mode: Wireless clients can access to the internet services, GWN7000 router and the access points GWN76xx but they cannot communicate with other Wireless clients. P a g e 42

43 This field is required when using Client Isolation, so users will not lose access to the Network (usually Internet). Gateway MAC Address Type in the default LAN Gateway s MAC address (router s MAC address for instance) in hexadecimal separated by :. Example: 00:0B:82:8B:4D:D8 RSSI Enabled Minimum RSSI (dbm) Enable Voice Enterprise Enable 11R Enable 11K Enable 11V Upstream Rate Downstream Rate Check to enable RSSI function, this will lead the AP to disconnect users below the configured threshold in Minimum RSSI (dbm). Enter the minimum RSSI value in dbm. If the signal value is lower than the configured minimum value, the client will be disconnected. The input range is from -94 or -1. Enable this feature to help clients of APs connected to the GWN7000 to perform better roaming decision. The k standard helps clients to speed up the search for nearby APs that are available as roaming targets by creating an optimized list of channels. When the signal strength of the current AP weakens, your device will scan for target APs from this list. When your client device roams from one AP to another on the same network, r uses a feature called Fast Basic Service Set Transition (FT) to authenticate more quickly. FT works with both pre-shared key (PSK) and 802.1X authentication methods. 11R, 11V, 11K respectively represents the feature sets the three protocols r, v, k specifies, enterprise audio is a function based on these feature sets, and 11R is required, without this function, the enterprise audio will be unavailable. Set a limitation of upload speed on the SSID. Set a limitation of download speed on the SSID. Device Membership: Used to add or remove paired access points to the network group. P a g e 43

44 Figure 19: Device Membership Click on to add the GWN76xx to the network group, or click on to remove it. Wi-Fi Schedule: Used to schedule the times when the Wi-Fi is ON or OFF. In the below example, the Wi-Fi is scheduled to be active Monday starting from 8:00 AM until 5:00 PM. Note: The hour field is in 24 format (from 0 to 23). Valid range for minutes is P a g e 44

45 Figure 20: Wi-Fi Schedule Note: The schedule feature is based on SSID and not network group, meaning that you can schedule the broadcasting of different SSID on different periods of the day. Users can Also add a device to a Network Group from Access Points Page: - Select the desired AP to add to a Network Group and click on. P a g e 45

46 Figure 21: Add AP to Network Group from Access Points Page - Check to select the desired Network, on which the selected APs will be added, as shown in the above figure. Create an SSID under a Network Group Under Network Group Page, click to edit a network group or create a new network group and go to Wi-Fi tab. P a g e 46

47 Refer to [Table 20: Wi-Fi] for Wi-Fi options. Figure 22: Create an SSID Additional SSID under Same Network Group GWN7000 provides the ability to create an additional SSID under the same group. To create an additional SSID go to Network Group Additional SSID. P a g e 47

48 Figure 23: Additional SSID Select one of the available network groups from Network Group Membership dropdown menu; this will create an additional SSID with the same Device Membership configured when creating the main network group. Figure 24: Additional SSID Created Click on to delete the additional SSID, or to edit it. P a g e 48

49 Client Bridge The Client Bridge feature allows an access point to be configured as a client for bridging wired only clients wirelessly to the network. When an access point is configured in this way, it will share the WiFi connection to the LAN ports transparently. This is not to be confused with a mesh setup. The client will not accept wireless clients in this mode. Once a Network Group has an Client Bridge Support enabled, the AP adopted in this Network Group can be turned in to Bridge Client mode by click the Bridge button. Please be noted that once an AP it turned into Client Bridge mode, it cannot be controlled by a Master anymore, and a factory reset is required to turn it back into normal AP mode. Important Notes: Figure 25: Client Bridge The access point that will be operating on bridge mode, must be set with a fixed IP address before activating the bridge mode on the access point. Users must enable client bridge support option under network group or SSID WiFi settings in order to have it fully functional. See [Client Bridge Support] P a g e 49

50 CLIENTS CONFIGURATION Clients Connected clients to different network groups can be shown and managed from a single interface. Clients list can be accessed from GWN7000 s Web GUI Clients to perform different actions to wired and wireless clients. GWN7000 Enterprise Router with its DHCP server enabled on LAN ports level, will assign automatically an IP address to the devices connected to its LAN ports like a computer or GWN76xx access points and to wireless clients connected to paired GWN76xx access points. Figure 26: Clients Click on under Actions to check a client s status and modify its configuration. Status Used to check user s basic information such as MAC address, IP address, which Network group does it belong to, and to which access point if it is a wireless client, as well as Throughput and Aggregate usage. P a g e 50

51 Figure 27: Client's Status Edit IP and Name Configuration tab allowing to set a name for a client and set a static IP. Figure 28: Client's Configuration Bandwidth Rules As mentioned on the BANDWIDTH RULES section, users can set bandwidth rules for upstream and downstream links per SSID, or per Client. For Clients users can set bandwidth rules by navigating to the menu Client Edit Bandwidth Rules then click add new item. P a g e 51

52 The following figure shows the settings: Figure 29: Client Bandwidth Rules Block a client To block a client, click on MAC list under Router Port Global Settings. under actions, this will add automatically the blocked client to Banned Client Figure 30: Block a Client To unban a client, go to Router Port Global Settings. Click on to remove it from the banned list. Figure 31: Unban Client Clients Access From this menu, users can manage in global and way the blacklist of clients that will be blocked from accessing the WiFi network, click on global blacklist. to add or remove MAC addresses of client from P a g e 52

53 Figure 32: Global Blacklist Figure 33: Managing the Global Blacklist A second option, is to add custom access lists that will be used as matching mechanism for MAC address filtering option under network groups and SSIDs to allow (whitelist) or disallow (blacklist) clients access to the WiFi network. Click on in order to create new access list, then fill it with all MAC addresses to be matched. Once this is done, this access list can be used under network group or SSID WiFi settings to filter clients either using whitelist or blacklist mode. Figure 34: Blacklist Access List Time Policy The timed client disconnect feature allows the system administrator to set a fixed time for which clients should be allowed to connect to the access point, after which the client will no longer be allowed to connect for a user configurable cool-down period. The configuration is based on a policy where the administrator can set the amount of time for which clients are allowed to connect to the WiFi and reconnect type and value after which they will be allowed to connect back after they have been disconnected. P a g e 53

54 In order to create a new policy, go under Clients Time Policy and add new one., then the following parameters: Table 21: Time Policy Parameters Option Name Enabled Limit Client Connection Time Client Reconnect Timeout Type Client Reconnect Timeout Reset Day Reset Hour Description Enter the name of the policy Check the box to enable the policy Sets amount of time a client may be connected. Select the method with which we will reset a client s connection timer so they may reconnect again. Options are: Reset Daily. Reset Weekly. Reset Hourly. Timed Reset. If Timed Reset is selected, this is the period for which the client will have to wait before reconnecting. If Reset Weekly is selected, this is the day the reset will be applied. If Reset Weekly or Reset Daily is select, this is the hour and day the reset will be applied. Note: Time tracking shall be accounted for on a per-policy basis, such that a client connected to any SSID assigned the time tracking policy will accrue a common counter, regardless of which SSID they are connected to (as long as those SSIDs all share the same time tracking policy). Banned Clients Click on to view the list of the clients that have been banned after time disconnect feature has taken effect, these clients will not be allowed to connect back until timeout reset or you can unblock a client by clicking on the icon. Figure 35: Ban/Unban Client P a g e 54

55 VPN (VIRTUAL PRIVATE NETWORK) Overview VPN allows the GWN7000 to be connected to a remote VPN server using PPTP, L2TP/IPSec and OpenVPN protocols, or configure an OpenVPN server and generate certificates and keys for clients, VPN page can be accessed from the GWN7000 Web GUI VPN. OpenVPN Server Configuration To use the GWN7000 as an OpenVPN server, you will need to start creating OpenVPN certificates and client certificates. Before generating server/client certificates, it is requested to generate first the Certificate Authority (CA), which will help to issue server/clients certificates. GWN7000 certificates can be managed from WebGUI System Settings Cert. Manager. Generate Self-Issued Certificate Authority (CA) A certificate authority (CA) is a trusted entity that issues electronic documents that verify a digital entity's identity on the Internet. The electronic documents (a.k.a. digital certificates) are an essential part of secure communication and play an important part in the public key infrastructure (PKI). To create a Certification Authority (CA), follow below steps: 1. Navigate to System Settings Cert. Manager CAs on the GWN7000 web GUI. 2. Click on button. A popup window will appear. 3. Enter the CA values including CN, Key Length, and Digest algorithm depending on your needs. Refer to below figure showing an example of configuration and below table showing all available options with their respective description. P a g e 55

56 Figure 36: Create CA Certificate Table 22: CA Certificate Field Description Enter the common name for the CA. Common Name It could be any name to identify this certificate. Example: CATest. Choose the key length for generating the CA certificate. Following values are available: Key Length 1024: 1024-bit keys are no longer sufficient to protect against attacks. 2048: 2048-bit keys are a good minimum. (Recommended). P a g e 56

57 4096: 4096-bit keys are accepted by nearly all RSA systems. Using 4096-bit keys will dramatically increase generation time, TLS handshake delays, and CPU usage for TLS operations. Choose the digest algorithm: SHA1: This digest algorithm provides a 160-bit fingerprint Digest Algorithm output based on arbitrary length input. SHA-256: This digest algorithm generates an almostunique, fixed size 256-bit (32-byte) hash. Hash is a one-way function it cannot be decrypted back. Lifetime (days) Country Code State or Province City Organization Organization Unit Address Enter the validity date for the CA certificate in days. In our example, set to 120. Select a country code from the dropdown list. Example: MA. Enter a state name or province. Example: Casablanca. Enter a city name. Example: Casablanca. Enter the organization name. Example: GS. Enter the organization unit name. Example: Gs. Enter an address. Example: grandstream@gmail.com 4. Click on button after completing all the fields for the CA certificate. 5. Click on button to export the CA to local computer. The CA file has extension.crt. P a g e 57

58 Figure 37: CA Certificate Generate Server/Client Certificates Create both server and client certificates for encrypted communication between clients and GWN7000 acting as an OpenVPN server. Creating Server Certificate To create server certificate, follow below steps: 1. Navigate to System Settings Cert. Manager Certificates. 2. Click on button. A popup window will appear. Refer to below figure showing an example of configuration and below table showing all available options with their respective description. P a g e 58

59 Figure 38: Generate Server Certificates Table 23: Server Certificate Field Common Name Description Enter the common name for the server certificate. It could be any name to identify this certificate. Example: ServerCertificate. CA Certificate Select CA certificate previously generated from the drop-down list. Example: CATest. P a g e 59

60 Choose the certificate type from the drop-down list. It can be either Certificate Type a client or a server certificate. Choose Server to generate server certificate. Choose the key length for generating the server certificate. Following values are available: Key Length 1024: 1024-bit keys are no longer sufficient to protect against attacks. Not recommended. 2048: 2048-bit keys are a good minimum. Recommended. 4096: 4096-bit keys are accepted by nearly all RSA systems. Using 4096-bit keys will dramatically increase generation time, TLS handshake delays, and CPU usage for TLS operations. Choose the digest algorithm: SHA1: This digest algorithm provides a 160-bit fingerprint Digest Algorithm output based on arbitrary length input. SHA-256: This digest algorithm generates an almostunique, fixed size 256-bit (32-byte) hash. Hash is a one-way function it cannot be decrypted back Lifetime (days) Country Code State or Province City Organization Address Enter the validity date for the server certificate in days. In our example, set to 120. Select a country code from the dropdown list. Example: MA. Enter a state name or province. Example: Casablanca. Enter a city name. Example: Casablanca. Enter the organization name. Example: GS. Enter an address. Example: Cert@grandstream.com. 3. Click on button after completing all the fields for the server certificate. P a g e 60

61 Click on button to export the server certificate file in.crt format. Click on button to export the server key file in. key format. Click on button to revoke the server certificate if no longer needed. Notes: The server certificates (.crt and.key) will be used by the GWN7000 when acting as a server. The server certificates (.crt and.key) can be exported and used on another OpenVPN server. Creating Client Certificate To create client certificate, follow below steps: 1- Create Users a. Navigate to System Settings User Manager. b. Click on button. The following window will pop up. Figure 39: User Management c. Enter User information based on below descriptions. P a g e 61

62 Field Enabled Full Name Username Password IPSec Pre-Shared Key Description Check to enable the user. Choose full name to identify the users. Choose username to distinguish client s certificate. Enter user password for each username. Enter the pre-shared key to connect to VPN server. This field is used when clients are using pre-shared key. d. Repeat above steps for each user. 2- Create Client Certificate a. Navigate under System Settings Cert. Manager Certificates. b. Click on button. The following window will pop up. c. Enter client certificate information based on below descriptions. P a g e 62

63 Figure 40: Client Certificate Table 24: Client Certificate Field Common Name CA Certificate Certificate Type Description Enter the common name for the client certificate. It could be any name to identify this certificate. Example: ClientCertificate. Select the generated CA certificate from the drop-down list. Choose the certificate type from the drop-down list. It can be either a client or server certificate. P a g e 63

64 Username Select created user to generate his certificate. Choose the key length for generating the client certificate. Following values are available: 1024: 1024-bit keys are no longer sufficient to protect against attacks. Not recommended. Key Length 2048: 2048-bit keys are a good minimum. Recommended. 4096: 4096-bit keys are accepted by nearly all RSA systems. Using 4096-bit keys will dramatically increase generation time, TLS handshake delays, and CPU usage for TLS operations. Choose the digest algorithm: SHA1: This digest algorithm provides a 160-bit fingerprint Digest Algorithm output based on arbitrary length input. SHA-256: This digest algorithm generates an almostunique, fixed size 256-bit (32-byte) hash. Hash is a one-way function it cannot be decrypted back Lifetime (days) Country Code State or Province City Organization Address Enter the validity date for the client certificate in days. Example: 120. Select a country code from the dropdown list. Example: MA. Enter a state name or province. Example: Casablanca. Enter a city name. Example: Casablanca. Enter the organization name. Example: GS. Enter an address. Example: user@grandstream.com. d. Click on after completing all the fields for the client certificate. e. Click on to export the client certificate file in.crt format. f. Click on to export the client key file in.key format. P a g e 64

65 Click on to revoke the client certificate if no longer needed. The client certificates (.crt and.key ) will be used by clients connected to the GWN7000 in order to establish TLS handshake. Notes: Client certificates generated from the GWN7000 need to be uploaded to the clients. For security improvement, each client needs to have his own username and certificate, this way even if a user is compromised, other users will not be affected. Create OpenVPN Server Once client and server certificates are successfully created, you can create a new server, so that clients can be connected to it, by navigating under VPN OpenVPN Server. To create a new VPN server, follow below steps: 1. Click on and the following window will pop up. P a g e 65

66 Figure 41: Create OpenVPN Server Table 25: OpenVPN Server Field Enable VPN Name Server Mode Description Click on the checkbox in order to enable the OpenVPN server feature. Enter a name for the OpenVPN server. Choose the server mode the OpenVPN server will operate with. 4 modes are available: P a g e 66

67 PSK: used to establish a point-to-point OpenVPN configuration. A VPN tunnel will be created with a server endpoint of a specified IP and a client endpoint of specified IP. Encrypted communication between client and server will occur over UDP port 1194, the default OpenVPN port. SSL: Authentication is made using certificates only (no user/pass authentication). Each user has a unique client configuration that includes their personal certificate and key. This is useful if clients should not be prompted to enter a username and password, but it is less secure as it relies only on something the user has (TLS key and certificate). User Auth: Authentication is made using only CA, user and password, no certificates. Useful if the clients should not have individual certificates. Less secure as it relies on a shared TLS key plus only something the user knows (Username/password). SSL + User Auth: Requires both certificate and username / password. Each user has a unique client configuration that includes their personal certificate and key. Most secure, as there are multiple factors of authentication (TLS Key and Certificate that the user has, and the username/password they know). Protocol Interface Local Port Encryption Algorithm Choose the Transport protocol from the dropdown list, either TCP or UDP. The default protocol is UDP. Select the interface used to connect the GWN7000 to the uplink, either WAN1, WAN2 or All. Configure the listening port for OpenVPN server. The default value is Choose the encryption algorithm from the drop-down list, in order to encrypt data so that the receiver can decrypt it using same algorithm. Choose the digest algorithm from the drop-down list, which will Digest Algorithm uniquely identify the data to provide data integrity and ensure that the receiver has an unmodified data from the one sent by the original host. P a g e 67

68 TLS Authentication TLS Pre-Shared Key Certificate Authority Server Certificate IPv4 Tunnel Network Redirect Gateway Automatic Firewall Rule Auto Forward Group Traffic LZO Compression Allow Peer to Change IP This option uses a static Pre-Shared Key (PSK) that must be generated in advance and shared among all peers. This feature adds extra protection to the TLS channel by requiring that incoming packets have a valid signature generated using the PSK key. Enter the generated TLS Pre-Shared Key when using TLS Authentication. Select a generated CA from the drop-down list. Select a generated Server Certificate from the drop-down list. Enter the network range that the GWN7000 will be serving from to the OpenVPN client. Note: The network format should be the following /16. The mask should be at least 16 bits. When redirect-gateway is used, OpenVPN clients will route DNS queries through the VPN, and the VPN server will need to handle them. Enable automatic firewall rule. If enabled, choose which groups you want to forward, if not, you can manually configure the forward rules under firewall settings. Select whether to activate LZO compression or no, if set to Adaptive, the server will make the decision whether this option will be enabled or no. Allow remote change the IP and/or Port, often applicable to the situation when the remote IP address changes frequently. 2. Click after completing all the fields. 3. Click on top of the WebGUI in order to apply changes. Figure 42: OpenVPN P a g e 68

69 OpenVPN Client configuration The GWN7000 act as both, an OpenVPN client and server, once users and client certificate created, navigate under VPN OpenVPN Client and follow steps below: 1. Click on and the following window will pop up. Figure 43: OpenVPN Client P a g e 69

70 Table 26: OpenVPN Client Field Enable VPN Name Description Click on the checkbox to enable the OpenVPN client feature. Enter a name for the OpenVPN client. Protocol Choose the Transport protocol from the dropdown list, either TCP or UDP. The default protocol is UDP. Interface Select the interface used to connect the GWN7000 to the uplink, either WAN1, WAN2 or All. Local Port Configure the listening port for OpenVPN server. Default is Remote OpenVPN Server Remote OpenVPN Server Port Configure the remote OpenVPN server IP address. Configure the remote OpenVPN server port. Choose the server mode the OpenVPN server will operate with, 4 modes are available: PSK: used to establish a point-to-point OpenVPN configuration. A VPN tunnel will be created with a server endpoint of a specified IP and a client endpoint of specified IP. Encrypted communication between client and server will occur over UDP port 1194, the default OpenVPN port. Auth Mode SSL: Authentication is made using certificates only (no user/pass authentication). Each user has a unique client configuration that includes their personal certificate and key. This is useful if clients should not be prompted to enter a username and password, but it is less secure as it relies only on something the user has (TLS key and certificate). User Auth: Authentication is made using only CA, user and password, no certificates. Useful if the clients should not have individual certificates. Less secure as it relies on a shared TLS key plus only something the user knows (Username/password). SSL + User Auth: Requires both certificate and username / password. Each user has a unique client configuration that includes their personal certificate and key. Most secure, as there are multiple factors of authentication (TLS Key and Certificate that the user has, and the username/password they know). P a g e 70

71 Encryption Algorithm Digest Algorithm TLS Authentication TLS Pre-Shared Key Auto Forward Group Traffic Network Group Routes Don t Pull Routes Force Default Route through Server IP Masquerading LZO Compression Allow Peer to Change IP CA Certificate Client Certificate Choose the encryption algorithm from the drop-down list, in order to encrypt data so that the receiver can decrypt it using the same algorithm. Choose the digest algorithm from the drop-down list, which will uniquely identify the data to provide data integrity and ensure that the receiver has an unmodified data from the one sent by the original host. This option uses a static Pre-Shared Key (PSK) that must be generated in advance and shared among all peers. This feature adds extra protection to the TLS channel by requiring that incoming packets have a valid signature generated using the PSK key. Enter the generated TLS Pre-Shared Key when using TLS Authentication. If enabled, choose which groups you want to forward, if not, you can manually configure the forward rules under firewall settings. Select the Network group to which the client belongs, or select All Network Groups. This feature allows specifying and adding custom routes. If enabled, client will ignore routes pushed by the server. Force a default route to the server. This feature is a form of network address translation (NAT) which allows internal computers with no known address outside their network, to communicate to the outside. It allows one machine to act on behalf of other machines. LZO encoding provides a very high compression ratio with good performance. LZO encoding works especially well for CHAR and VARCHAR columns that store very long character strings. Allow remote change the IP and/or Port, often applicable to the situation when the remote IP address changes frequently. Click on Upload and select the CA certificate generated previously on this guide. Click on Upload and select the Client Certificate generated previously on this guide. P a g e 71

72 Client Private Key Client Private Key Password Click on Upload and select the Client Private Key generated previously on this guide. Enter the client private key password 2. Click after completing all the fields. 3. Click on top of the webgui in order to apply changes. Figure 44: OpenVPN Client L2TP/IPSEC Configuration Layer 2 Tunneling Protocol (L2TP) is a tunneling protocol used to support virtual private networks (VPNs) or as part of the delivery of services by ISPs. It does not provide any encryption or confidentiality by itself. Rather, it relies on an encryption protocol that it passes within the tunnel to provide privacy. GWN7000 L2TP/IPSec Client Configuration To configure L2TP client on the GWN7000, navigate under VPN L2TP/IPSec and set the following: 1- Click on and the following window will pop up. P a g e 72

73 Figure 45: L2TP Client Configuration Table 27: L2TP Configuration Field Enable VPN Name WAN Port Remote L2TP Server Username Password Description Click on the checkbox in order to enable the L2TP client feature. Enter a name for the L2TP client. Select which WAN port is connected to the uplink, either WAN1 or WAN2. Enter the IP/Domain of the remote L2TP Server. Enter the Username for authentication against the VPN Server. Enter the Password for authentication against the VPN Server. P a g e 73

74 Select either Transport mode or Tunnel mode: Connection Type Transport mode is commonly used between end stations or between an end station and a gateway, if the gateway is being treated as a host. Tunnel mode is used between gateways, or at an end station to a gateway, the gateway acting as a proxy for the hosts behind it. Pre-Shared Key Auto Forward Group Traffic Enter the L2TP pre-shared key. If enabled, choose which groups you want to forward, if not, you can manually configure the forward rules under firewall settings. Configures the remote subnet for the VPN. Remote Subnet Use Tunnel as Default Route IP Masquerading Use DNS from Server Number of Attempts to Reconnect Use Built-in IPv6 management Port Forwarding Rules Port Trigger Rules The format should be IP/Mask where IP could be either IPv4 or IPv6 and mask is a number between 1 and 32. For example: /24 Enable this option so that L2TP/IPSec VPN Tunnel will be used by default. This feature is a form of network address translation (NAT) which allows internal computers with no known address outside their network, to communicate to the outside. It allows one machine to act on behalf of other machines. Enable this option to retrieve DNS from the VPN server. Configures the number of attempts to reconnect the L2TP client, if this number is exceeded, the client will be disconnected from the L2TP/IP Server. Enable the IPv6 management for the VPN. Enter the port-forwarding rule to be used for the VPN. Enter the port trigger rule to be used for the VPN. 2- Click after completing all the fields. 3- Click on top of the web GUI to apply changes. P a g e 74

75 Figure 46: L2TP Client PPTP CONFIGURATION A data-link layer protocol for wide area networks (WANs) based on the Point-to-Point Protocol (PPP) and developed by Microsoft that enables network traffic to be encapsulated and routed over an unsecured public network such as the Internet. Point-to-Point Tunneling Protocol (PPTP) allows the creation of virtual private networks (VPNs), which tunnel TCP/IP traffic through the Internet. GWN7000 Client Configuration To configure PPTP client on the GWN7000, navigate under VPN PPTP and set the following: 1- Click on and the following window will pop up. P a g e 75

76 Figure 47: PPTP Client Configuration Table 28: PPTP Configuration Field Enable VPN Name Remote PPTP Server Description Click on the checkbox to enable the PPTP VPN client feature. Enter a name for the PPTP client. Enter the IP/Domain of the remote PPTP Server. P a g e 76

77 Username Password Auto Forward Group Traffic Subnet Use Tunnel as Default Route IP Masquerading Use DNS from Server Number of Attempts to Reconnect Use Built-in IPv6 management MPPE Port Forwarding Rules Port Trigger Rules Enter the Username for authentication against the VPN Server. Enter the Password for authentication against the VPN Server. If enabled, choose which groups you want to forward, if not, you can manually configure the forward rules under firewall settings. Configures the remote subnet for the VPN. The format should be IP/Mask where IP could be either IPv4 or IPv6 and mask is a number between 1 and 32. For example: /24 Enable this option so that PPTP VPN Tunnel will be used by default. This feature is a form of network address translation (NAT) which allows internal computers with no known address outside their network, to communicate to the outside. It allows one machine to act on behalf of other machines. Enable this option to retrieve DNS from the VPN server. Configures the number of attempts to reconnect the PPTP client, if this number is exceeded, the client will be disconnected from the PPTP Server. Enable the IPv6 management for the VPN. Enable / disable the MPPE for data encryption. By default, it s disabled. Enter the port-forwarding rule to be used for the VPN. Enter the port trigger rule to be used for the VPN. 2- Click after completing all the fields. 3- Click on top of the webgui to apply changes. Figure 48: PPTP Client P a g e 77

78 GWN7000 PPTP Server Configuration To configure PPTP server on the GWN7000, go to VPN PPTP Server and set the following: 1- Click on and the following window will pop up. Figure 49: PPTP Server Configuration Table 29: PPTP Server Configuration Parameters Field Enable VPN Name Description Click on the checkbox to enable the PPTP VPN Server. Enter a name for the PPTP Server. PPTP Server Address Configure the PPTP server local address (ex: ). P a g e 78

79 Client Start Address Client End Address Allow Forwarding between Site-To-Site VPNs MPPE Auto Forward group traffic Network Group Configure the remote client IP start address. Note: this address should be in the same subnet as the end address and PPTP server address. Configure the remote client IP end address. Note: this address should be in the same subnet as the start address and PPTP server address. This option allows forwarding between multiple site-to-site VPNs. i.e. if there are multiple PPTP users configured with client subnet enabled, then this option allows one PPTP client subnet to access another PPTP client subnet through the server. Note: for this option to work more than one PPTP users with client subnet must be enabled. Enable / disable the MPPE for data encryption. By default, it s disabled. Configures if enable group traffic forwards to be automatic. If enabled, users should choose which groups they want to forward, if not, users can still do it manually via forwarding rules under firewall settings. Note: if cancel check, the previous group settings will be cleared, user need to re-configure the groups. Configure the network group to access VPN connection, you can choose more than one network group at the same time. 2- Click after completing all the fields. 3- Click on top of the web GUI to apply changes. After this step, you need to create user accounts under web GUI System Settings User Manager in order to connected to the configured PPTP server. P a g e 79

80 FIREWALL GWN7000 supports firewall feature to control incoming and outgoing traffic by restricting or rejecting specific traffic, as well as preventing attacks to the GWN7000 networks for enhanced security. The Firewall feature includes 3 menus: Basic Settings: Used to enable SYN Flood, setup port forwarding, DMZ, inter-group traffic forwarding and UPnP. Traffic Rules: Used to control incoming/outgoing traffic in customized scheduled times, and taking actions for specified rules such as Accept; Reject and Drop. Advanced: Used to setup SNAT and DNAT. Basic Settings General Settings SYN Flood Protection is used to avoid DOS attacks. SYN Flood Protection is enabled by default on GWN7000, you can edit the SYN Flood Rate Limit, SYN Flood Burst Limit and whether to drop or no the invalid packets as shown in the below screenshot Figure 50: Basic General Settings Port Forwarding Port forwarding allows redirecting a communication request from one address and port number combination to another. Below are different possible actions: To add a Port Forward rule, click on. To edit a Port Forward rule, click on. To delete a Port Forward rule, click on. P a g e 80

81 Figure 51: Port Forward Refer to following table for Port Forwarding option when editing or creating a port-forwarding rule: Table 30: Port Forward Name Enabled Protocol Source Group Source Port Destination Group Destination IP Destination Port Specify a name for the port forward rule. Check to enable this port forward rule. Select a protocol, users can select TCP, UDP or TCP/UDP. Select the WAN Interface. Set the Source Port number. Select the LAN group. Set the destination IP address. Set the Destination Port number. DMZ GWN7000 support DMZ, where it is possible to specify a LAN client to be put on the DMZ. To add an IP into the DMZ, click on. To edit a DMZ entry, click on. To delete a DMZ entry, click on. P a g e 81

82 Refer to below table for DMZ fields: Figure 52: DMZ Table 31: DMZ Name Enabled Source Group Destination Group Destination IP Specify a name for the DMZ entry. Check to enable this DMZ entry. Select the WAN interface Select the LAN group. Set the destination IP address. Inter-Group Traffic Forwarding GWN7000 offers the possibility to allow traffic between different groups and interfaces. Users can select to edit a source group and add to it other network groups and WAN interfaces to allow inter-group traffic between the selected members. Figure 53: Inter-group Traffic Forwarding Click on next to source group, and click on to add groups and interfaces to selected groups, or click on to remove members from selected groups as shown in below figure P a g e 82

83 Figure 54: Enabling inter-group traffic UPnP GWN7000 supports UPnP that enables programs running on a host to configure automatically port forwarding. UPnP allows a program to make the GWN7000 to open necessary ports, without any intervention from the user, without making any check. UPnP settings can be accessed from GWN7000 WebGUI Firewall Basic UPnP Settings. Refer to below Table for UPnP settings. Table 32: UPnP Settings Enable Daemon Check to enable Daemon for UPnP. External Interface Select the WAN interface to allow external connection to resources that enables UPnP. Internal Interface Check the LAN network group on which to activate UPnP. Enable UPnP Check to Enable UPnP for the LAN clients on selected network group. Enable NAT-PMP Check to enable automatic NAT Port Mapping (NAT-PMP). Secure Mode Check to activate secure mode for devices that activate UPnP. Logging to Syslog Choose whether to log activities for UPnP into Syslog. Download Speed Set the Download speed value in KB/s. Default is 2048 Upload Speed Set the Upload speed value in KB/s. Default is P a g e 83

84 Traffic Rules Settings GWN7000 offers the possibility to fully control incoming/outgoing traffic for different protocols in customized scheduled times, and taking actions for specified rules such as Accept; Reject and Drop. Following actions are available to configure Input, output and forward rules for configured protocols To add new rule, Click on. To edit a rule, Click on. To delete a rule, Click on. Figure 55: Traffic Rules Settings Refer to below table for each tab, when editing or creating a traffic rule: Table 33: Firewall Traffic Rules Name Enabled IP Family Source Group Protocol Source IP Address Specify a name for the traffic rule. Check to enable this rule. Select the IP version, three options are available: IPv4, IPv6 or Any. Select a WAN interface or a LAN group for Source Group, or select All. Select one of the protocols from dropdown list or All, available options are: UDP, TCP, TCP/UCP, UDP-Lite, ICMP, AH, SCTP, IGMP and All. Set the Source IP address, it can be an IPv4 or IPv6 address. P a g e 84

85 Source MAC address Destination IP Destination Port(s) Set the Source MAC address. Set the destination IP address, it can be an IPv4 or IPv6 address. Set the destination s port(s). Schedule Start Date Click on icon to schedule a start date for this rule to be applied. Schedule End Date Click on icon to schedule an end date for this rule to cease effect. Schedule Start Time Click on icon to schedule a start time for this rule to be applied. Schedule End Time Click on icon to schedule an end time for this rule to cease effect. Schedule Weekdays List of Weekdays Schedule Days of the Month Treat Time Values as UTC Instead of Local Time Firewall Action Select the days, on which the traffic rule will be applied, the unselected days will ignore this rule. Enter the days of the months (separated by space) on which the traffic rule will be applied. Example: This will be applied only on 5 th, 10 th and 15 th day monthly. Check to use UTC as time zone for the specified times, instead of using GWN7000 s local time. Select which action to perform for the given traffic rule, 3 options are available: Accept, Reject or Drop. Firewall Advanced Settings Firewall Advanced Settings page provides the ability to setup input/output policies for each WAN interface and LAN groups; as well as setting configuration for Static and Dynamic NAT. General Settings Click on next to a WAN interface or Network group to edit its input and output policies. Refer to below table for general settings options Table 34: Firewall-General Settings Select which action to apply to all incoming traffic to this interface/lan Input Policy group, 3 actions are available: Accept, Reject and Drop. Select which action to apply to all outgoing traffic from this interface/lan Output Policy group, 3 actions are available: Accept, Reject and Drop. Check to enable IP Masquerading, this will allow internal computers with IP Masquerading no known address outside their network, to communicate to the outside. It allows one machine to act on behalf of other machines. P a g e 85

86 MSS Clamping Log Dropped and Reject Traffic to Syslog Limit for Dropped and Rejected Traffic Check to enable MSS Clamping. This will provide a method to prevent fragmentation when the MTU value on the communication path is lower than the MSS value. Check to send all rejected and dropped traffic logs to configured Syslog Server. Specify the limit for dropped and reject traffic. The value format is N/unit, where N is a digit number, and unit can either be in second, minute, hour or day. SNAT Following actions are available for SNAT. To add new SNAT entry, click on. To edit a SNAT entry, click on. To delete a SNAT rule, click on. Refer to below table when creating or editing an SNAT entry Table 35: SNAT Name Enabled IP Family Source Group Destination Group Protocol Source IP Rewrite IP Destination IP Specify a name for the SNAT entry Check to enable this SNAT entry. Select the IP version, three options are available: IPv4, IPv6 or Any. Select a WAN interface or a LAN group for Source Group, or select All. Select a WAN interface or a LAN group for Destination Group, or select All. Make sure that destination and source groups are different to avoid conflict. Select one of the protocols from dropdown list or All, available options are: UDP, TCP, TCP/UCP and All. Set the Source IP address. Set the Rewrite IP. The source IP address of the data package from the source group will be updated to this configured IP. Set the Destination IP address. Schedule Start Date Click on applied. icon to schedule a start date for this SNAT entry to be Schedule End Date Click on icon to schedule an end date for this SNAT entry to end. P a g e 86

87 Schedule Start Time Click on applied. icon to schedule a start time for this SNAT entry to be Schedule End Time Click on icon to schedule an end time for this SNAT entry to end. Schedule Weekdays List of Weekdays Schedule Days of the Month Treat Time Values as UTC Instead of Local Time Select the days, on which the SNAT entry will be applied, the unselected days will ignore this rule. Enter the days of the months (separated by space) on which the SNAT entry will be applied. Example: This will be applied only on 5 th, 10 th and 15 th day monthly. Check to use UTC as time zone for the specified times, instead of using GWN7000 s local time. DNAT Following actions are available for DNAT: To add new DNAT entry, click on. To edit a DNAT entry, click on. To delete a DNAT rule, click on. Refer to below table when creating or editing a DNAT entry: Table 36: DNAT Name Enabled IP Family Source Group Destination Group Protocol Source IP Rewrite IP Destination IP Specify a name for the DNAT entry Check to enable this DNAT entry. Select the IP version, three options are available: IPv4, IPv6 or Any. Select a WAN interface or a LAN group for Source Group, or select All. Select a WAN interface or a LAN group for Destination Group, or select All. Make sure that destination and source groups are different to avoid conflict. Select one of the protocols from dropdown list or All, available options are: UDP, TCP, TCP/UCP and All. Set the Source IP address. Set the Rewrite IP. The source IP address of the data package from the source group will be updated to this configured IP. Set the Destination IP address. P a g e 87

88 Schedule Start Date Click on applied. icon to schedule a start date for this DNAT entry to be Schedule End Date Click on icon to schedule an end date for this DNAT entry to end. Schedule Start Time Click on applied. icon to schedule a start time for this DNAT entry to be Schedule End Time Click on icon to schedule an end time for this DNAT entry to end. Schedule Weekdays List of Weekdays Schedule Days of the Month Treat Time Values as UTC Instead of Local Time Enable NAT Reflection Select the days, on which the DNAT entry will be applied, the unselected days will ignore this rule. Enter the days of the months (separated by space) on which the DNAT entry will be applied. Example: This will be applied only on 5 th, 10 th and 15 th day monthly. Check to use UTC as time zone for the specified times, instead of using GWN7000 s local time. Check to enable NAT Reflection for this DNAT entry to allow the access of a service via the public IP address from inside the local network. P a g e 88

89 CAPTIVE PORTAL Captive Portal feature on GWN7000 Router allows to define a Landing Page (Web page) that will be displayed on Wi-Fi clients browsers when attempting to access Internet. Once connected to a GWN76xx AP paired with the router, Wi-Fi clients will be forced to view and interact with that landing page before Internet access is granted. The Captive Portal feature can be configured from the GWN7000 Web page, by navigating to Captive Portal. The page contains three tabs: Policy, Files and Clients. Policy Configuration Page The policy configuration page contains options for authentication type used when enabling the captive portal feature. The following table describes all the settings on this page: Table 37: Basic Configuration Page Field Name Expiration Authentication Type RADIUS Server Address Description Enter a name to identify the created landing page. Enter the expiration time for the landing page, this field must contain an integer between from 60 to (in minutes). If this field is set to 0 the landing page will never expire. Choose the authentication type from dropdown list, three types of authentication are available: No Authentication: when choosing this option, the landing page feature will not provide any type of authentication, it will instead prompt users to accept the license agreement to gain access to internet. RADIUS Server: choosing this option will allow users to set a RADIUS server to authenticate clients connected to the router. WeChat: choosing this option will allow users to log in using WeChat app. Enter the IP address or the FQDN of the RADIUS server used for authenticating clients. RADIUS Server Port Enter the RADIUS server port, by default tis P a g e 89

90 RADIUS Server Secret ShopId Enter the shared key between authenticator and RADIUS server. Enter the ShopId for WeChat. AppId Enter the AppId for WeChat. SecretKey Portal Page Customization Enter the SecretKey for WeChat authentication. This option provides users to choose the landing page that will be shown once a client tries to connect to the GWN, two pages are available: Portal Default: This page is used when no authentication is specified, users will only need to accept license agreement to gain access to internet. Portal Pass: This option provides authentication textbox when using RADIUS authentication mode, in order to enter username and identity stored in RADIUS database. Files Configuration Page Files configuration page allows users to view and upload HTML pages and related files (images ). The captive portal uses two HTML pages using authentication scenarios, either portal_default.html which doesn t provide authentication and is only accepting license agreement, while portal_pass.html provides textboxes for authentication, Wired or Wi-Fi clients will be redirected to one of these pages before accessing Internet. The following figure shows portal_default.html page: P a g e 90

91 The following figure shows portal_pass.html page: Figure 56: portal_default.html page Figure 57: portal_pass.html page P a g e 91

92 The following figure shows default files used for Captive Portal: Click to upload a new Web page. Figure 58: Files Settings Page Click to add a new folder. Click to upload files to the selected folder. Folder can be selected from the dropdown list. Clients Page Clients page lists MAC addresses of authenticated devices using captive portal. Figure 59: Client Web Page P a g e 92

93 BANDWIDTH RULES The bandwidth rule is a GWN7000 feature that allows users to limit bandwidth utilization per SSID, MAC address or IP address. This option can be configured from the GWN7000 WebGUI under Bandwidth Rules. Click to add a new rule, the following table provides an explanation about different options for bandwidth rules. Table 38: Bandwidth Rules Field Description Type Choose the type of rules to apply for bandwidth utilization from the dropdown list, three options are available: SSID: Set a bandwidth limitation on the SSID level. MAC: Set a bandwidth limitation per MAC address. IP Address: Set a bandwidth limitation per IP address. SSID MAC Select the SSID to which the limitation will be applied, this option appears only when SSID type is selected. Enter the MAC address of the device to which the limitation will be applied, this option appears only when MAC type is selected. IP address Network Group Upstream Rate Downstream Rate Enter the IP address of the device to which the limitation will be applied, this option appears only when IP Address type is selected. Choose the network group to which belongs the device, this option is available when choosing either MAC or IP address type. Specify the limit for the upload bandwidth using Kbps or Mbps. Specify the limit for the download bandwidth using Kbps or Mbps. The following figure shows an example of MAC address rule limitation. P a g e 93

94 Figure 60: MAC Address Bandwidth rule The following figure shows examples of bandwidth rules: Figure 61: Bandwidth Rules P a g e 94

95 MAINTENANCE AND TROUBLESHOOTING GWN7000 offers multiple tools and options for maintenance and debugging to help further troubleshooting and monitoring the GWN7000 resources. Maintenance Maintenance page can be accessed from GWN7000 WebGUI System Settings Maintenance. Refer to below table for maintenance tabs and fields. Table 39: Maintenance Basic Web WAN Access Enable the web WAN access. By default, it s disabled Web HTTP Access Enable the web HTTP Access. By default, it s disabled. Web HTTPS Port Specifies the HTTPS port. By default, is 443. Country Select the country from the drop-down list. Time Zone Configure time zone for the GWN7000. Please reboot the device to take effect. NTP Server Configure the IP address or URL of the NTP server, the device will obtain the date and time from the configured server. Date Display Format Change the Date Display Format, three options are possible YYYY/MM/DD, MM/DD/YYYY and DD/MM/YYYY Upgrade Authenticate Config File Authenticate configuration file before acceptance. Default is disabled. Enter the password for encrypting the XML configuration file using OpenSSL. XML Config File Password The password is used to decrypt the XML configuration file if it is encrypted via OpenSSL. Upgrade Via Specify uploading method for firmware and configuration. 3 options are available: HTTP, HTTPS and TFTP. Firmware Server Configure the IP address or URL for the firmware upgrade server. Config Server Configure the IP address or URL for the configuration file server. Choose whether to enable or disable automatic upgrade and provisioning Check Update on Boot after reboot. Default is disabled. Automatic Upgrade Check Interval(m) Specify the time period to check for firmware upgrade (in minutes). Reboot Click on Reboot button to reboot the device Download Configuration Click on Download to download the device s configuration file. P a g e 95

96 Upgrade Now Factory Reset Current Administrator Password New Administrator Password Confirm New Administrator Password User Password User Password Confirmation Syslog Server Syslog Level Click on Upgrade, to launch firmware/config file provisioning. Please make sure to Save and Apply changes before clicking on Upgrade. Click on Reset to restore the GWN7000 as well as all online GWN76xx units to factory default settings Access Enter the current administrator password Change the current password. This field is case sensitive with a maximum length of 32 characters. Enter the new administrator password one more time to confirm. Configure the password for user-level Web GUI access. This field is case sensitive with a maximum length of 32 characters. Enter the new User password again to confirm. Syslog Enter the IP address or URL of Syslog server. Please reboot the GWN7000 to take effect. Select the level of Syslog, 5 levels are available: None, Debug, Info, Warning and Error. Please reboot the GWN7000 to take effect. Logserver The logserver page allows the user to configure syslog server on GWN7000 in order to save log messages on connected external USB drive. First connect a USB drive to the Access point, then configure the parameters and make sure to start the server in order to collect messages from devices sending syslog to GWN. Following table gives description for configuration parameters of GWN Logserver: Option Enable WAN Firewall Rule Logrotate File Size Logrotate File Count Logrotate Mode Description Enable WAN Firewall rules to allow incoming syslog messages to the router. Select the size of file to trigger rotation, if left empty, then the router will use only the Logrotate frequency rules to trigger rotation. Select the Maximum number of rotates files to keep. Default is 56 files. Choose the time rotation frequency mode (default every 3 hours). Every X hours (0-23) Every X Minutes (0-59). P a g e 96

97 X hour of day (0-23). X day of week (Sunday-Saturday) + X hour of day (0-23). Hours Minutes Hour of the day Day of the week Devices Enable Logserver Enter the number of hours period after which trigger file rotation. Enter the number of Minutes period after which trigger file rotation. Enter the hour of day at which trigger file rotation. Enter Day of the week + hour of day, at which trigger file rotation. Select the path (a USB partition) to store collected logs. Required. Enables the logserver After settings up the logserver and saving the settings, users need to connect a USB external storage and press Start button in order to start collecting logs. All log messages from all devices will be put on one single file, and the router will keep rotating and creating new files based on the configured rotation policy. P a g e 97

98 Figure 62: Logserver Configuration Debug Many debugging tools are available on GWN7000 s WebGUI to check the status and troubleshoot GWN7000 s services and networks. Debug page offers 4 tabs: Capture, Ping/Traceroute, Syslog and Nat Table. Capture This section is used to capture packet traces from the GWN7000 interfaces (WAN ports and network groups) for troubleshooting purpose or monitoring... It is needed to plug an USB storage device to one of the USB ports on the back of the GWN7000. Click on to start capturing on a certain device plugged to the USB port. Click on to stop the capture. P a g e 98

99 Click on to show the captured files on a chosen device, and the capture files details will appear, click on to delete all files, click on next to a capture file to download it on a local folder, or click on to delete it. Figure 63: Capture Files The below table will show different fields used on capture page Table 40: Debug-Capture File Name Interface Device File Size Rotate Count Direction Source Port Destination Port Source IP Dest IP Protocol Enter the name of the capture file that will be generated. Choose an Interface (WAN port1 or 2, or a network group) from where to begin the capture. Choose a device plugged to USB port to save the capture once started. Set a File size that the capture will not exceed (Optional field). Set a value for rotating captures (Optional Field). Choose if you want to get all traffic or only outgoing or incoming to the choses interface. Set the Source Port to filter capture traffic coming from the defined source port. Set the Destination Port to filter capture traffic coming from the defined port. Set the Source IP to filter capture traffic coming from the defined source IP. Set the Destination IP to filter capture traffic coming from the defined destination IP. Choose ALL or a specific protocol to capture (IP, ARP, RARP, TCP, UDP, ICMP, IPv6) Ping/Traceroute Ping and Traceroute are useful debugging tools to verify reachability with other clients across the network (WAN or LAN). The GWN7000 offers both Ping and Traceroute tools for IPv4 and IPv6 protocols. P a g e 99

100 To use these tools, go to GWN7000 WebGUI System Settings Debug and click on Ping/Traceroute. Figure 64: IP Ping Next to Tool choose from the dropdown menu: - IPv4 Ping for an IPv4 Ping test to Target - IPv6 Ping for an IPv6 Ping test to Target - IPv4 Traceroute for an IPv4 Traceroute to Target - IPv6 Traceroute for an IPv6 Traceroute to Target Type in the destination s IP address/domain name in Target field. Click on Run. P a g e 100

101 Figure 65: Traceroute Syslog GWN7000 supports dumping the syslog information to a remote server under Web GUI System Settings Maintenance Syslog. Enter the syslog server hostname or IP address and select the level for the syslog information. Five levels of syslog are available: None, Debug, Info, Warning, and Error. Syslog messages are also displayed in real time under Web GUI System Settings Debug Syslog. P a g e 101

102 Figure 66: Syslog NAT Table NAT table is updated dynamically on GWN7000 s WebGUI, to check the NAT table go to System Settings Debug NAT Table. P a g e 102

103 Figure 67: NAT table /Notification The /Notification page allows the administrator to select a predefined set of system events and to send notifications upon the change of the set events. Note: A reboot is required in order to activate notification feature. Table 41: Setting Filed Enabled Host Port Username Password Address Description Enable/disable the settings. By default, it s disabled Configures the SMTP Server IP or Domain Name. Specifies the Port number used by server to send . Specifies sender s User ID or account ID in the system used. Specifies sender s password of the account. Specifies the address of the administer where to receive notifications. P a g e 103

104 The following table describe the notifications configuration settings. Table 42: Events Filed Enabled Memory Usage Memory Usage Threshold (%) CPU Usage CPU Usage Threshold (%) Firmware upgrade Add/Remove Network Group Additional SSID Time Zone Change Administrator Password Change AP Offline Description Enable/disable the notification. By default, it s disabled Configures whether to send notification if memory usage is greater than the configured threshold. By default, it s disabled. Specifies the Memory Usage Threshold (%). Must be integer between 1 and 100. Configures whether to send notification if CPU usage is greater than the configured threshold. By default, it s disabled. Specifies the CPU Usage Threshold (%). Must be integer between 1 and 100. Configures whether to send notification on firmware upgrade. Default is disabled. Configures whether to send notification when network groups has been added/removed. Configures whether to send notification if any additional SSID is enabled. Default is disabled. Configures whether to send notification on time zone change. Default is disabled. Configures whether to send notification on admin password change. Default is disabled. Configures whether to send notification when AP going offline. Default is disabled. LED Schedule GWN7000 supports the LED schedule feature. This feature is used to set the timing of the LEDs to stay ON and when they will go OFF at customer s convenience. This can be useful for example when the LEDs become disturbing during some periods of the day. This way with the LED schedule, you can set the timing so that the LEDs turn off at night after specific hours and maintain the Wi-Fi service for other clients without shutting down the AP. To configure LED schedule, on the GWN7000 WebGUI navigate to System Settings LEDs. Following options are available: Table 43: LED Schedule settings Option LEDs Always off Description Turn off completely the LEDs. P a g e 104

105 Schedule Start Hour Schedule Start Minute Schedule Stop Hour Schedule Stop Minute Schedule weekdays list Configure the hour when LEDs will be automatically turned on. Configure the minute when LEDs will be automatically turned on. Configure the hour when LEDs will be automatically turned off. Configure the minute when LEDs will be automatically turned off. Choose the days for which you want to schedule the LEDs. Following example set the LEDs to be turned on from 8am till 8pm every day: Figure 68: LED Schedule File Sharing The GWN7000 has 2 USB ports that can be also used for file sharing, to enable file sharing on devices plugged on the USB ports, go to System Settings File Sharing. Click on to share a directory and its contents on a device connected to one of the USB ports of the GWN7000, the following figure will pop up. P a g e 105

106 Figure 69: Add a New File to Share Table 44: Add a New File to Share Share Name Path to Share Access to Share Comment Share Accessible by Network Groups Enter the share name Choose from the drop menu the path to share. Choose whether to allow users to Read/Write or Read Only on the shared path. Enter a comment for the added shared file. Choose whether to allow All LAN network groups to access the shared path, restrict access by selecting only some groups or None. Edit a Shared Folder by clicking on or delete it by clicking on. Figure 70: File Share Actions A device connected to one of the allowed network groups to the shared files can use the following path for access: \\GWN_Address\Share_Name\ Where GWN_Address is the GWN7000 IP address, and Share_Name is the Share Name created for the File Share. It is also possible to map a network drive on Windows, or use a Samba client on Linux machine. P a g e 106

107 Figure 71: Access File Share SNMP GWN7000 supports SNMP (Simple Network Management Protocol) which is widely used in network management for network monitoring for collecting information about monitored devices. To configure SNMP settings, go to GWN7000 Web GUI System Settings SNMP, this page has two tabs: Basic and Advanced, refer to the below tables for each tab. Table 45: SNMP Basic Page System Location System Contact System Name Read-Only Community for IPv4 Set the System Location information, for example: SNMP-Server Lobby GWN. Set the System Contact information, for example: Contact Supervisor_GWN via extension is Set the System Name information, for example: Supervisor_GWN. Gives the permission for the set community to access and read only to devices in management information base via IPv4 Protocol. Read-Write Community for IPv4 Read-Only Community for IPv6 Gives the permission for the set community to access and read/write to devices in management information base via IPv4 Protocol. Gives the permission for the set community to access and read only to devices in management information base via IPv6 Protocol. P a g e 107

Grandstream Networks, Inc.

Grandstream Networks, Inc. Grandstream Networks, Inc. GWN7000 Enterprise Multi-WAN Gigabit VPN Router User Manual COPYRIGHT 2017 Grandstream Networks, Inc. http://www.grandstream.com All rights reserved. Information in this document

More information

Grandstream Networks, Inc.

Grandstream Networks, Inc. Grandstream Networks, Inc. GWN7000 Enterprise Multi-WAN Gigabit VPN Router User Manual COPYRIGHT 2016 Grandstream Networks, Inc. http://www.grandstream.com All rights reserved. Information in this document

More information

Grandstream Networks, Inc. GWN76xx Wi-Fi Access Points Master/Slave Architecture Guide

Grandstream Networks, Inc. GWN76xx Wi-Fi Access Points Master/Slave Architecture Guide Grandstream Networks, Inc. GWN76xx Wi-Fi Access Points Master/Slave Architecture Guide Table of Contents INTRODUCTION... 4 DISCOVER AND PAIR GWN76XX ACCESS POINTS... 5 Discover GWN76xx... 5 Method 1: Discover

More information

Grandstream Networks, Inc.

Grandstream Networks, Inc. Grandstream Networks, Inc. GWN7000 Enterprise Router & Access Point Manager COPYRIGHT 2016 Grandstream Networks, Inc. http://www.grandstream.com All rights reserved. Information in this document is subject

More information

Grandstream Networks, Inc. GWN7000 Command Line Guide

Grandstream Networks, Inc. GWN7000 Command Line Guide Grandstream Networks, Inc. Table of Contents INTRODUCTION... 3 CONNECTING AND ACCESSING THE GWN7XXX... 4 Connecting the GWN7000... 4 SSH Access... 5 USING THE CLI MENU... 6 Menu Structure And Navigation...

More information

Grandstream Networks, Inc. GWN76xx Wi-Fi Access Points Standalone Guide

Grandstream Networks, Inc. GWN76xx Wi-Fi Access Points Standalone Guide Grandstream Networks, Inc. GWN76xx Wi-Fi Access Points Standalone Guide Table of Content INTRODUCTION... 3 USING DEFAULT SSID... 4 USING CUSTOM SSID... 5 Discover GWN76xx... 5 Method 1: Discover GWN76xx

More information

GWN7000 Firmware Release Note IMPORTANT UPGRADING NOTE

GWN7000 Firmware Release Note IMPORTANT UPGRADING NOTE GWN7000 Firmware Release Note IMPORTANT UPGRADING NOTE If your GWN7000 has firmware version lower than 1.0.2.62 (1.0.2.62 not included), please refer to the beta forum upgrade guide or contact tech support

More information

Grandstream Networks, Inc.

Grandstream Networks, Inc. Grandstream Networks, Inc. GWN Cloud Cloud based Access Points Controller User Guide COPYRIGHT 2018 Grandstream Networks, Inc. http://www.grandstream.com All rights reserved. Information in this document

More information

Grandstream Networks, Inc. GWN7000 QoS - VoIP Traffic Management

Grandstream Networks, Inc. GWN7000 QoS - VoIP Traffic Management Grandstream Networks, Inc. GWN7000 QoS - VoIP Traffic Management Table of Contents INTRODUCTION... 4 DSCP CLASSIFICATION... 5 QUALITY OF SERVICE ON GWN7000... 6 USING QOS TO PRIORITIZE VOIP TRAFFIC...

More information

GWN7000 Firmware Release Note IMPORTANT UPGRADING NOTE

GWN7000 Firmware Release Note IMPORTANT UPGRADING NOTE GWN7000 Firmware Release Note IMPORTANT UPGRADING NOTE 2 intermedia upgrading are required from 1.0.1.x to 1.0.2.62. Please refer to 1.0.2.62 release note for upgrading steps. Controller module of any

More information

Grandstream Networks, Inc.

Grandstream Networks, Inc. Grandstream Networks, Inc. GWN7610 Enterprise 802.11ac WiFi Access Point User Manual COPYRIGHT 2017 Grandstream Networks, Inc. http://www.grandstream.com All rights reserved. Information in this document

More information

Grandstream Networks, Inc.

Grandstream Networks, Inc. Grandstream Networks, Inc. GWN7610 Enterprise 802.11ac WiFi Access Point User Manual COPYRIGHT 2017 Grandstream Networks, Inc. http://www.grandstream.com All rights reserved. Information in this document

More information

Grandstream Networks, Inc.

Grandstream Networks, Inc. Grandstream Networks, Inc. GWN7610 Enterprise 802.11ac WiFi Access Point User Manual COPYRIGHT 2017 Grandstream Networks, Inc. http://www.grandstream.com All rights reserved. Information in this document

More information

Security SSID Selection: Broadcast SSID:

Security SSID Selection: Broadcast SSID: 69 Security SSID Selection: Broadcast SSID: WMM: Encryption: Select the SSID that the security settings will apply to. If Disabled, then the device will not be broadcasting the SSID. Therefore it will

More information

Grandstream Networks, Inc.

Grandstream Networks, Inc. Grandstream Networks, Inc. GWN7610 Enterprise 802.11ac WiFi Access Point User Manual COPYRIGHT 2018 Grandstream Networks, Inc. http://www.grandstream.com All rights reserved. Information in this document

More information

Grandstream Networks, Inc. GWN7600 Mid-Tier ac Wave-2 WiFi Access Point User Manual

Grandstream Networks, Inc. GWN7600 Mid-Tier ac Wave-2 WiFi Access Point User Manual Grandstream Networks, Inc. GWN7600 Mid-Tier 802.11ac Wave-2 WiFi Access Point User Manual COPYRIGHT 2017 Grandstream Networks, Inc. http://www.grandstream.com All rights reserved. Information in this document

More information

User Manual. AC ac Wireless Access Point/Router. Model WAC124. NETGEAR, Inc.

User Manual. AC ac Wireless Access Point/Router. Model WAC124. NETGEAR, Inc. AC2000 802.11ac Wireless Access Point/Router Model WAC124 December 2018 202-11885-02 NETGEAR, Inc. 350 E. Plumeria Drive San Jose, CA 95134, USA AC2000 802.11ac Support Thank you for purchasing this NETGEAR

More information

Grandstream Networks, Inc.

Grandstream Networks, Inc. Grandstream Networks, Inc. GWN7600LR Enterprise 802.11ac Wave-2 Outdoor Long Range WiFi Access Point User Manual COPYRIGHT 2017 Grandstream Networks, Inc. http://www.grandstream.com All rights reserved.

More information

Grandstream Networks, Inc. GWN7600 Mid-Tier ac Wave-2 WiFi Access Point User Manual

Grandstream Networks, Inc. GWN7600 Mid-Tier ac Wave-2 WiFi Access Point User Manual Grandstream Networks, Inc. GWN7600 Mid-Tier 802.11ac Wave-2 WiFi Access Point User Manual COPYRIGHT 2017 Grandstream Networks, Inc. http://www.grandstream.com All rights reserved. Information in this document

More information

Grandstream Networks, Inc. GWN7600 Enterprise ac Wave-2 WiFi Access Point User Manual

Grandstream Networks, Inc. GWN7600 Enterprise ac Wave-2 WiFi Access Point User Manual Grandstream Networks, Inc. GWN7600 Enterprise 802.11ac Wave-2 WiFi Access Point User Manual COPYRIGHT 2016 Grandstream Networks, Inc. http://www.grandstream.com All rights reserved. Information in this

More information

Grandstream Networks, Inc.

Grandstream Networks, Inc. Grandstream Networks, Inc. GWN7600LR Outdoor Long Range 802.11ac Wave-2 WiFi Access Point User Manual COPYRIGHT 2017 Grandstream Networks, Inc. http://www.grandstream.com All rights reserved. Information

More information

Grandstream Networks, Inc. GWN7600 Enterprise ac Wave-2 WiFi Access Point User Manual

Grandstream Networks, Inc. GWN7600 Enterprise ac Wave-2 WiFi Access Point User Manual Grandstream Networks, Inc. GWN7600 Enterprise 802.11ac Wave-2 WiFi Access Point User Manual COPYRIGHT 2016 Grandstream Networks, Inc. http://www.grandstream.com All rights reserved. Information in this

More information

GWN7600/GWN7600LR Firmware Release Note

GWN7600/GWN7600LR Firmware Release Note GWN7600/GWN7600LR Firmware Release Note Table of Content FIRMWARE VERSION 1.0.4.12... 2 PRODUCT NAME... 2 DATE... 2 ENHANCEMENT... 2 BUG FIX... 2 KNOWN ISSUE... 3 NEW FEATURE OVERVIEW... 3 FIRMWARE VERSION

More information

GWN7610 Firmware Release Note IMPORTANT UPGRADING NOTE

GWN7610 Firmware Release Note IMPORTANT UPGRADING NOTE GWN7610 Firmware Release Note IMPORTANT UPGRADING NOTE 1. Before starting to upgrade, please make sure your GWN7610 s firmware version is 1.0.2.108 or higher. 2. Before starting to upgrade, please make

More information

Grandstream Networks, Inc.

Grandstream Networks, Inc. Grandstream Networks, Inc. GWN.Cloud Cloud based Access Points Controller User Guide COPYRIGHT 2018 Grandstream Networks, Inc. http://www.grandstream.com All rights reserved. Information in this document

More information

GWN7610 Firmware Release Notes IMPORTANT UPGRADING NOTE

GWN7610 Firmware Release Notes IMPORTANT UPGRADING NOTE GWN7610 Firmware Release Notes IMPORTANT UPGRADING NOTE 1. Please upgrade to 1.0.4.22 to get the patch for WPA2 4-way handshake vulnerability. 2. Before starting to upgrade, please make sure your GWN7610

More information

GWN7600 Firmware Release Note IMPORTANT UPGRADING NOTE

GWN7600 Firmware Release Note IMPORTANT UPGRADING NOTE GWN7600 Firmware Release Note IMPORTANT UPGRADING NOTE 1. For firmware 1.0.5.13, this is only for GWN7610/GWN7600/GWN7600LR master deployment. All users with GWN7000 as master are NOT encouraged to upgrade

More information

GWN7600/7600LR Firmware Release Notes IMPORTANT UPGRADING NOTE

GWN7600/7600LR Firmware Release Notes IMPORTANT UPGRADING NOTE GWN7600/7600LR Firmware Release Notes IMPORTANT UPGRADING NOTE 1. For firmware 1.0.5.13, this is only for GWN7610/GWN7600/GWN7600LR master deployment. All users with GWN7000 as master are NOT encouraged

More information

GWN7610 Firmware Release Note IMPORTANT UPGRADING NOTE

GWN7610 Firmware Release Note IMPORTANT UPGRADING NOTE GWN7610 Firmware Release Note IMPORTANT UPGRADING NOTE 1. For firmware 1.0.5.14, this is only for GWN7610 master deployment. All users with GWN7000 as master are NOT encouraged to upgrade until 1.0.5.x

More information

Grandstream Networks, Inc.

Grandstream Networks, Inc. Grandstream Networks, Inc. GWN7610 Enterprise 802.11ac WiFi Access Point User Manual COPYRIGHT 2016 Grandstream Networks, Inc. http://www.grandstream.com All rights reserved. Information in this document

More information

User Manual DIR-850L. Wireless AC1200 Dual Band Gigabit Router.

User Manual DIR-850L. Wireless AC1200 Dual Band Gigabit Router. User Manual DIR-850L Wireless AC1200 Dual Band Gigabit Router USER MANUAL: DIR-850L Wireless AC1200 Dual Band Gigabit Router SYSTEM REQUIREMENTS Network Requirements Web-based Configuration Utility Requirements

More information

Cisco CVR100W Wireless-N VPN Router with Highly Secure Business-Class Connectivity for Small Offices/Home Offices (SOHO)

Cisco CVR100W Wireless-N VPN Router with Highly Secure Business-Class Connectivity for Small Offices/Home Offices (SOHO) Data Sheet Cisco CVR100W Wireless-N VPN Router with Highly Secure Business-Class Connectivity for Small Offices/Home Offices (SOHO) The Cisco CVR100W Wireless-N VPN Router provides easy-to-use, affordable,

More information

User Manual. Rev:

User Manual.   Rev: Default Login Details Login Address: www.mykasda.com Login Password: Set up by users Default Wi-Fi SSID: Kasda xxxx KW6516 (Printed on product label) Default Wi-Fi Password: 12345678 www.kasdanet.com Rev:

More information

KX/3G ADSL2+ ROUTER MAIN FEATURES

KX/3G ADSL2+ ROUTER MAIN FEATURES The KORTEX 3G/ADSL2+, a dual-wan 3G / ADSL2+ firewall router integrated with the 802.11g wireless access point and 4-port switch, is a cutting-edge networking product for SOHO and office users. Uniquely,

More information

VPN Routers DSR-150/250/500/1000AC. Product Highlights. Features. Overview. Comprehensive Management Capabilities. Web Authentication Capabilities

VPN Routers DSR-150/250/500/1000AC. Product Highlights. Features. Overview. Comprehensive Management Capabilities. Web Authentication Capabilities Product Highlights Comprehensive Management Solution Advanced features such as WAN failover, load balancing, and integrated firewall help make this a reliable, secure, and flexible way to manage your network.

More information

Unified Services Routers

Unified Services Routers Product Highlights Comprehensive Management Solution Active-Active WAN port features such as auto WAN failover and load balancing, ICSA-certified firewall, and D-Link Green Technology make this a reliable,

More information

User Manual DIR-615. Wireless Router with Built-in 4-port Switch

User Manual DIR-615. Wireless Router with Built-in 4-port Switch DIR-615 Wireless Router with Built-in 4-port Switch December 2011 Contents Chapter 1. Introduction...4 Contents and Audience...4 Conventions...4 Document Structure...4 Chapter 2. Overview...5 General Information...5

More information

Calix T07xG HGU ONT Operation and Maintenance Guide

Calix T07xG HGU ONT Operation and Maintenance Guide Calix T07xG HGU ONT Operation and Maintenance Guide July 2013 #220-00589, Rev 10 Contents About This Document... 5 Revision History... 6 Product Introduction... 7 Chapter 1: ONT Configuration... 11 Web

More information

WRE6606. User s Guide. Quick Start Guide. Dual-Band Wireless AC1300 Access Point. Default Login Details. Version 1.00 (ABDU.0) Edition 1, 10/2016

WRE6606. User s Guide. Quick Start Guide. Dual-Band Wireless AC1300 Access Point. Default Login Details. Version 1.00 (ABDU.0) Edition 1, 10/2016 WRE6606 Dual-Band Wireless AC1300 Access Point Version 1.00 (ABDU.0) Edition 1, 10/2016 Quick Start Guide User s Guide Default Login Details Web Address http://zyxelsetup http://dhcp-assigned IP www.zyxel.comhttp://192.168.1.2

More information

802.11ac Wireless Access Point Model WAC104

802.11ac Wireless Access Point Model WAC104 Point Model WAC104 User Manual October 2016 202-11698-01 350 E. Plumeria Drive San Jose, CA 95134 USA Support Thank you for purchasing this NETGEAR product. You can visit www.netgear.com/support to register

More information

User Manual DIR-615. Wireless N 300 Home Router

User Manual DIR-615. Wireless N 300 Home Router DIR-615 Wireless N 300 Home Router April 2013 Contents Chapter 1. Introduction...5 Contents and Audience...5 Conventions...5 Document Structure...5 Chapter 2. Overview...6 General Information...6 Specifications...7

More information

AirCruiser G Wireless Router GN-BR01G

AirCruiser G Wireless Router GN-BR01G AirCruiser G Wireless Router GN-BR01G User s Guide i Contents Chapter 1 Introduction... 1 Overview...1 Features...1 Package Contents...2 AirCruiser G Wireless Router Rear Panel...2 AirCruiser G Wireless

More information

Section 3 - Configuration. Enable Auto Channel Scan:

Section 3 - Configuration. Enable Auto Channel Scan: Enable Auto Channel Scan: Wireless Channel: The Auto Channel Scan setting can be selected to allow the DGL-4500 to choose the channel with the least amount of interference. Indicates the channel setting

More information

AC2600 MU-MIMO Wi-Fi Router

AC2600 MU-MIMO Wi-Fi Router AC2600 MU-MIMO Wi-Fi Router Affordable & High-Performance 1733Mbps + 800Mbps Dual Band Wi-Fi Superior Wi-Fi Coverage MU-MIMO Smart Connect Highlights 4 Antennas&Beamforming for Maximum Coverage MU-MIMO

More information

CHAPTER 7 ADVANCED ADMINISTRATION PC

CHAPTER 7 ADVANCED ADMINISTRATION PC ii Table of Contents CHAPTER 1 INTRODUCTION... 1 Broadband ADSL Router Features... 1 Package Contents... 3 Physical Details... 4 CHAPTER 2 INSTALLATION... 6 Requirements... 6 Procedure... 6 CHAPTER 3 SETUP...

More information

LevelOne. User Manual. WAP Mbps PoE Wireless AP V3.0.0

LevelOne. User Manual. WAP Mbps PoE Wireless AP V3.0.0 LevelOne WAP-0005 108Mbps PoE Wireless AP User Manual V3.0.0 i TABLE OF CONTENTS CHAPTER 1 INTRODUCTION... 1 FIGURE 1: WIRELESS ACCESS POINT... 1 FEATURES OF YOUR WIRELESS ACCESS POINT... 1 Security Features...

More information

Covr your whole home in Seamless Wi-Fi

Covr your whole home in Seamless Wi-Fi Covr your whole home in Seamless Wi-Fi High Performance More Coverage One Seamless Network TRI-BAND WHOLE HOME WI-FI SYSTEM COVR-2202/2200 USER MANUAL Preface D-Link reserves the right to revise this publication

More information

D-Link DSR Series Router

D-Link DSR Series Router D-Link DSR Series Router U s e r M a n u a l Copyright 2010 TeamF1, Inc. All rights reserved Names mentioned are trademarks, registered trademarks or service marks of their respective companies. Part No.:

More information

Datasheet. Gigabit Routers with SFP. Models: ER-4, ER-6P. Sophisticated Routing Features. Next-Generation Price/Performance Value

Datasheet. Gigabit Routers with SFP. Models: ER-4, ER-6P. Sophisticated Routing Features. Next-Generation Price/Performance Value Datasheet Gigabit Routers with SFP Models: ER-4, ER-6P Sophisticated Routing Features Next-Generation Price/Performance Value SFP Port for Fiber Uplink Datasheet Overview Advanced Routing Technology for

More information

Meraki Z-Series Cloud Managed Teleworker Gateway

Meraki Z-Series Cloud Managed Teleworker Gateway Datasheet Z Series Meraki Z-Series Cloud Managed Teleworker Gateway Fast, Reliable Connectivity for the Modern Teleworker The Cisco Meraki Z-Series teleworker gateway is an enterprise class firewall, VPN

More information

User Manual Gemtek WiMAX Modem

User Manual Gemtek WiMAX Modem User Manual Gemtek WiMAX Modem WIXS-177 CONTENTS Chapter 1 Overview...1-1 1.1. Indoor CPE... 1-1 1.2. Outdoor CPE... 1-2 Chapter 2 WEB-GUI...2-3 2.1. System Configuration Login... 2-3 2.2. System Logout...

More information

Datasheet. Gigabit Router with SFP. Models: ER-4. Sophisticated Routing Features. Next-Generation Price/Performance Value. SFP Port for Fiber Uplink

Datasheet. Gigabit Router with SFP. Models: ER-4. Sophisticated Routing Features. Next-Generation Price/Performance Value. SFP Port for Fiber Uplink Gigabit Router with SFP Models: ER-4 Sophisticated Routing Features Next-Generation Price/Performance Value SFP Port for Fiber Uplink Overview Advanced Routing Technology for the Masses Internet Ubiquiti

More information

Peplink Balance Multi-WAN Routers

Peplink Balance Multi-WAN Routers Peplink Balance Multi-WAN Routers Model 20/30/210/310/380/390/580/710/1350 User Manual Firmware 5.1 September 10 Copyright & Trademarks Specifications are subject to change without prior notice. Copyright

More information

802.11b/g/n SOHO Router 2.4GHz 300Mbps 11N AP/Router

802.11b/g/n SOHO Router 2.4GHz 300Mbps 11N AP/Router 802.11b/g/n SOHO Router 2.4GHz 300Mbps 11N AP/Router ESR-9752 PRODUCT DESCRIPTION ESR-9752 is a 2T2R Wireless Single chip 11N Broadband Router that delivers up to 6x faster speeds and 3x extended coverage

More information

AC WiFi Business Access Point WAC510 User Manual

AC WiFi Business Access Point WAC510 User Manual AC WiFi Business Access Point WAC510 User Manual with NETGEAR Insight app for easy management December 2016 202-11686-01 350 E. Plumeria Drive San Jose, CA 95134 USA Support Thank you for purchasing this

More information

GWN76xx Firmware Release Notes IMPORTANT UPGRADING NOTE

GWN76xx Firmware Release Notes IMPORTANT UPGRADING NOTE GWN76xx Firmware Release Notes IMPORTANT UPGRADING NOTE 1. [6/15/2018] [GWN7600&7600LR 1.0.6.41] Starting from 1.0.6.x, GWN7600 and GWN7600LR will share same firmware file name. So, when changing an AP

More information

N150 WiFi DSL Modem Router Essentials Edition. N300 WiFi DSL Modem Router Essentials Edition

N150 WiFi DSL Modem Router Essentials Edition. N300 WiFi DSL Modem Router Essentials Edition N150 WiFi DSL Modem Router Essentials Edition Model D500 N300 WiFi DSL Modem Router Essentials Edition Model D1500 User Manual May 2018 202-11390-02 350 East Plumeria Drive San Jose, CA 95134 USA Support

More information

IP806GA/GB Wireless ADSL Router

IP806GA/GB Wireless ADSL Router IP806GA/GB Wireless ADSL Router 802.11g/802.11b Wireless Access Point ADSL Modem NAT Router 4-Port Switching Hub User's Guide Table of Contents CHAPTER 1 INTRODUCTION... 1 Wireless ADSL Router Features...

More information

Wireless Dual-Band N Router DWRT-600N

Wireless Dual-Band N Router DWRT-600N Wireless Dual-Band N Router DWRT-600N User Manual Quality Service Group Product name: Dual-Band N Router (DWRT-600N) Release Date: 2010/9 Manual Revision: V1.0 Web site: Email: www.brickcom.com technical@brickcom.com

More information

AC1200 WiFi Router User Manual

AC1200 WiFi Router User Manual AC1200 WiFi Router User Manual Model R6120 September 2017 202-11753-03 350 E. Plumeria Drive San Jose, CA 95134 USA Support Thank you for purchasing this NETGEAR product. You can visit www.netgear.com/support

More information

JN3919 LTE Indoor CPE Datasheet (Band38/40/41/42/43)

JN3919 LTE Indoor CPE Datasheet (Band38/40/41/42/43) JN3919 LTE Indoor CPE Datasheet (Band38/40/41/42/43) Version V1.01 Date 2016.3.30 1 Jaton Company will provide customers with comprehensive technical support. Any problem please contact support department

More information

Insight Managed Smart Cloud Wireless Access Point User Manual

Insight Managed Smart Cloud Wireless Access Point User Manual Insight Managed Smart Cloud Wireless Access Point User Manual Model WAC510 February 2018 202-11840-03 350 E. Plumeria Drive San Jose, CA 95134 USA Support Thank you for purchasing this NETGEAR product.

More information

1. Press "Speed Test" to find out your actual uplink and downlink speed.

1. Press Speed Test to find out your actual uplink and downlink speed. ASRock G10 Gaming Router 6.4 QoS Settings QoS Add Gaming Boost web page. Gaming Boost: Enable or disable the Gaming Boost. Bandwidth The router supports Gaming Boost natively, which identifies and intelligently

More information

AC1200 Dual Band Wireless Controller Kit TEW-821DAP2KAC (v1.0r)

AC1200 Dual Band Wireless Controller Kit TEW-821DAP2KAC (v1.0r) AC1200 Dual Band Wireless Controller Kit TEW-821DAP2KAC (v1.0r) Centralized AP management Includes two dual band wireless AC1200 access points with PoE injectors Wireless controller with five gigabit ports

More information

Grandstream Networks, Inc.

Grandstream Networks, Inc. Grandstream Networks, Inc. GWN7610/GWN7600/GWN7600LR Wireless Access Points User Manual GWN7610 Enterprise 802.11ac WiFi Access Point GWN7600 Mid-Tier 802.11ac Wave-2 WiFi Access Point GWN7600LR Outdoor

More information

Barracuda Link Balancer

Barracuda Link Balancer Barracuda Networks Technical Documentation Barracuda Link Balancer Administrator s Guide Version 2.3 RECLAIM YOUR NETWORK Copyright Notice Copyright 2004-2011, Barracuda Networks www.barracuda.com v2.3-111215-01-1215

More information

WISNETWORKS. WisOS 11ac V /3/21. Software version WisOS 11ac

WISNETWORKS. WisOS 11ac V /3/21. Software version WisOS 11ac WISNETWORKS User Manual V1.1 2016/3/21 Software version 1.0.0021 Table of contents 1. Setup& WMI... 3 1.1 Hardware Setup... 3 1.2 Web Management Interface... 3 2. Status... 4 2.1 Overview... 4 2.1.1 System...

More information

AC1900 Smart Wi-Fi Router

AC1900 Smart Wi-Fi Router AC1900 Smart Wi-Fi Router High-Speed Wi-Fi for Faster Connections Across Your Home 1300Mbps 5GHz + 600Mbps 2.4GHz Boosted Coverage Faster Wi-Fi with MU-MIMO Smart Connect Full Gigabit Ports Highlights

More information

AC1600 Wireless Dual Band Gigabit VoIP VDSL/ADSL Modem Router

AC1600 Wireless Dual Band Gigabit VoIP VDSL/ADSL Modem Router AC1600 Wireless Dual Band Gigabit VoIP VDSL/ADSL Modem Router Powerful Wi-Fi and Gigabit Wired for a High-Speed Home 300Mbps + 1300Mbps Dual Band Wi-Fi Gigabit Ports VoIP (2 FXS ports) Beamforming Technology

More information

AC3000 Tri-Band Wireless Gigabit Dual-WAN VPN SMB Router TEW-829DRU (v1.0r)

AC3000 Tri-Band Wireless Gigabit Dual-WAN VPN SMB Router TEW-829DRU (v1.0r) AC3000 Tri-Band Wireless Gigabit Dual-WAN SMB Router (v1.0r) Dual-WAN ports support load-balancing and fail-over modes 8 x Gigabit LAN ports, 1 x Console port SSL, IPsec, PPTP, and L2TP w/ipsec support

More information

AplombTech Smart Router Manual

AplombTech Smart Router Manual AplombTech Smart Router Manual (Version: 1.0) 1 Version & Purpose Version Manual version V 1.0 Explanation Corresponds to the initial version of device Purpose This manual describes the function features

More information

802.11N Wireless Broadband Router

802.11N Wireless Broadband Router 802.11N Wireless Broadband Router Pre-N Wireless Access Point Broadband Internet Access WPS 4-Port Switching Hub User's Guide Table of Contents CHAPTER 1 INTRODUCTION... 1 Wireless Router Features... 1

More information

Multi-Homing Broadband Router. User Manual

Multi-Homing Broadband Router. User Manual Multi-Homing Broadband Router User Manual 1 Introduction... 4 Features... 4 Minimum Requirements... 4 Package Content... 4 Note... 4 Get to know the Broadband Router... 5 Back Panel... 5 Front Panel...

More information

AC1350 Wireless Dual Band Router

AC1350 Wireless Dual Band Router AC1350 Wireless Dual Band Router Five antennas for faster AC Wi-Fi and greater coverage 450Mbps + 867Mbps Dual Band Wi-Fi MU-MIMO Technology for 2 Faster Performance Beamforming Technology for Better Coverage

More information

UIP1869V User Interface Guide

UIP1869V User Interface Guide UIP1869V User Interface Guide (Firmware version 0.1.8 and later) Table of Contents Opening the UIP1869V's Configuration Utility... 3 Connecting to Your Broadband Modem... 5 Setting up with DHCP... 5 Updating

More information

AC2300 Wireless MU-MIMO Gigabit Router

AC2300 Wireless MU-MIMO Gigabit Router A Wireless MU-MIMO Gigabit Router Best for Simultaneous 4K Streaming and Gaming 1625Mbps + 600Mbps Dual Band Wi-Fi 1.8GHz Dual-Core CPU MU-MIMO Smart Connect Range Boost Highlights MU-MIMO for 3 Faster

More information

LevelOne FBR User s Manual. 1W, 4L 10/100 Mbps ADSL Router. Ver

LevelOne FBR User s Manual. 1W, 4L 10/100 Mbps ADSL Router. Ver LevelOne FBR-1416 1W, 4L 10/100 Mbps ADSL Router User s Manual Ver 1.00-0510 Table of Contents CHAPTER 1 INTRODUCTION... 1 FBR-1416 Features... 1 Package Contents... 3 Physical Details... 3 CHAPTER 2

More information

AC2300 Wireless MU-MIMO Gigabit Router

AC2300 Wireless MU-MIMO Gigabit Router AC2300 Wireless MU-MIMO Gigabit Router Best for Simultaneous 4K Streaming and Gaming 1625Mbps + 600Mbps Dual Band Wi-Fi 1.8GHz Dual-Core CPU MU-MIMO Smart Connect Range Boost Highlights MU-MIMO for 3 Faster

More information

WISNETWORKS. WisOS 11ac V /3/21. Software version WisOS 11ac

WISNETWORKS. WisOS 11ac V /3/21. Software version WisOS 11ac WISNETWORKS User Manual V1.1 2016/3/21 Software version 1.0.0021 Table of contents 1. Setup& WMI... 3 1.1 Hardware Setup... 3 1.2 Web Management Interface... 3 2. Status... 4 2.1 Overview... 4 2.1.1 System...

More information

A5500 Configuration Guide

A5500 Configuration Guide A5500 Configuration Guide Sri Ram Kishore February 2012 Table of contents Gateway Configuration... 3 Accessing your gateway configuration tool... 3 Configuring your broadband Internet access... 3 Configuring

More information

Insight Managed Smart Cloud Wireless Access Point User Manual

Insight Managed Smart Cloud Wireless Access Point User Manual Insight Managed Smart Cloud Wireless Access Point User Manual Model WAC510 September 2017 202-11840-01 350 E. Plumeria Drive San Jose, CA 95134 USA Support Thank you for purchasing this NETGEAR product.

More information

DWR G Integrated Access Device. User Manual

DWR G Integrated Access Device. User Manual DWR-923 4G Integrated Access Device User Manual TABLE OF CONTENTS 1. GETTING TO KNOW THE DWR-923... 2 1.1 Introduction... 2 1.2 Package Contents... 3 1.3 System Requirements... 3 1.4 Hardware Overview

More information

AC750GW 750Mbps. Dual band Gigabit Wireless Router. Overview DATA SHEET. Highlights

AC750GW 750Mbps. Dual band Gigabit Wireless Router. Overview DATA SHEET. Highlights AC750GW 750Mbps Dual band Gigabit Wireless Router Highlights - 802.11ac/a/b/g/n, 750Mbps Wireless Speed - 3 x 7dBi fixed antennas - 2.4GHz and 5GHz Dual Band - Flexible bandwidth management to improve

More information

Orbi WiFi System User Manual

Orbi WiFi System User Manual User Manual February 2018 202-11675-09 350 E. Plumeria Drive San Jose, CA 95134 USA Support Thank you for purchasing this NETGEAR product. You can visit www.netgear.com/support to register your product,

More information

Quick Installation Guide

Quick Installation Guide Quick Installation Guide DL-200 Cellular Data logger V1.2_201610 TABLE OF CONTENTS CHAPTER 1 INTRODUCTION... 4 1.1 CONTENTS LIST... 5 1.2 HARDWARE INSTALLATION... 6 1.2.1 WARNING... 6 1.2.2 SYSTEM REQUIREMENTS...

More information

EVR b/g/n VPN Router PRODUCT DESCRIPTION

EVR b/g/n VPN Router PRODUCT DESCRIPTION 802.11b/g/n VPN Router 2.4GHz 300Mbps Gigabit 11N VPN PRODUCT DESCRIPTION is a 2T2R Wireless 11N Gigabit VPN Router that delivers up to 6x faster speeds and 3x extended coverage than 802.11g devices. supports

More information

Light Mesh AP. User s Guide. 2009/2/20 v1.0 draft

Light Mesh AP. User s Guide. 2009/2/20 v1.0 draft Light Mesh AP User s Guide 2009/2/20 v1.0 draft i FCC Certifications This equipment has been tested and found to comply with the limits for a Class B digital device, pursuant to Part 15 of the FCC Rules.

More information

NBG-416N. Wireless N-lite Home Router. Default Login Details. IMPORTANT! READ CAREFULLY BEFORE USE.

NBG-416N. Wireless N-lite Home Router. Default Login Details.  IMPORTANT! READ CAREFULLY BEFORE USE. NBG-416N Wireless N-lite Home Router IMPORTANT! Default Login Details LAN IP https://192.168.1.1 Address User Name admin Password 1234 READ CAREFULLY BEFORE USE. KEEP THIS GUIDE FOR FUTURE REFERENCE. IMPORTANT!

More information

Wireless USB Port Multi-Functional Printer Server. Model # AMPS240W. User s Manual. Ver. 1A

Wireless USB Port Multi-Functional Printer Server. Model # AMPS240W. User s Manual. Ver. 1A Wireless USB 2.0 1-Port Multi-Functional Printer Server Model # AMPS240W User s Manual Ver. 1A Table of Contents 1 Introduction...3 1.1 Package Contents... 3 1.2 System Requirements... 3 2 Multi-Functional

More information

User Guide TL-R470T+/TL-R480T REV9.0.2

User Guide TL-R470T+/TL-R480T REV9.0.2 User Guide TL-R470T+/TL-R480T+ 1910012468 REV9.0.2 September 2018 CONTENTS About This Guide Intended Readers... 1 Conventions... 1 More Information... 1 Accessing the Router Overview... 3 Web Interface

More information

GAN9.9T153A-B Product Specifications

GAN9.9T153A-B Product Specifications GAN9.9T153A-B Product All Rights Reserved. GAN9.9T153A-B Product Introduction The GAN9.9T153A-B is a high-performance wireless ADSL router, uplink rate up to 1 Mbps and downlink rate up to 24 Mbps. It

More information

Datasheet. 8-Port 10G SFP+ Router. Model: ER-8-XG. 80 Gbps Aggregate Throughput. 10G Ethernet SFP+ Ports. Hot-Swappable Modular Power Supplies

Datasheet. 8-Port 10G SFP+ Router. Model: ER-8-XG. 80 Gbps Aggregate Throughput. 10G Ethernet SFP+ Ports. Hot-Swappable Modular Power Supplies 8-Port 10G SFP+ Router Model: ER-8-XG 80 Gbps Aggregate Throughput 10G Ethernet SFP+ Ports Hot-Swappable Modular Power Supplies Example of Enterprise Deployment 10G Routing Technology for the Masses Ubiquiti

More information

AC1200M/MS. User Manual

AC1200M/MS. User Manual AC1200M/MS User Manual Table of Contents User Manual... 1 1 Preface... 1 2 LED Indicators and Connectors... 1 2.1 LED Indicators... 1 2.2 Hardware Installation... 2 3 Voice Prompt (AC1200MS)... 2 4 User

More information

Wireless 450N Dual-Band Gigabit Router 450 Mbps Wireless a/b/g/n, GHz, 3T3R MIMO, QoS, 4-Port Gigabit LAN Switch Part No.

Wireless 450N Dual-Band Gigabit Router 450 Mbps Wireless a/b/g/n, GHz, 3T3R MIMO, QoS, 4-Port Gigabit LAN Switch Part No. Wireless 450N Dual-Band Gigabit Router 450 Mbps Wireless 802.11a/b/g/n, 2.4 + 5 GHz, 3T3R MIMO, QoS, 4-Port Gigabit LAN Switch Part No.: 524988 Wireless 450N Dual-Band Router - The Ultimate in Wireless

More information

WAP9112/9114 Quick Start Guide

WAP9112/9114 Quick Start Guide WAP9112/9114 Quick Start Guide Release 7.6 NN47252-308 Issue 02.01 March 2016 Contents Chapter 1: Introduction... 3 Chapter 2: Required Software Components... 4 Chapter 3: Installing or Upgrading Wireless

More information

ADSL User Manual. Wireless-N BROADBAND ROUTER : Introduction

ADSL User Manual. Wireless-N BROADBAND ROUTER : Introduction ADSL User Manual 1 : Introduction The ADSL is a communication terminal, which integrates ADSL access, broadband SOHO router, WLAN and VoIP service. This device can provide high data transmission, downstream

More information

JNR1010v2 N150 Wireless Router User Manual

JNR1010v2 N150 Wireless Router User Manual User Manual January 2014 202-11340-02 350 East Plumeria Drive San Jose, CA 95134 USA Support Thank you for selecting NETGEAR products. After installing your device, locate the serial number on the label

More information

Cisco RV180 VPN Router

Cisco RV180 VPN Router Cisco RV180 VPN Router Secure, high-performance connectivity at a price you can afford. Figure 1. Cisco RV180 VPN Router (Front Panel) Highlights Affordable, high-performance Gigabit Ethernet ports allow

More information

RA21S User Manual / v1.0

RA21S User Manual / v1.0 RA21S User Manual 11-2016 / v1.0 CONTENTS I. Product Information... 1 I-1. Package Contents... 1 I-2. LED Status... 2 I-3. Back Panel... 3 I-4. Safety Information... 4 I-5. Reset to Factory Default Settings...

More information

DT-325 LiTE LTE Indoor CPE

DT-325 LiTE LTE Indoor CPE DT-325 LTE Indoor CPE Version V1.10 Date Aug. 26, 2015 Green Packet Berhad Company 1 Greenpacket will provide customers with comprehensive technical support. Any problem please contact support department

More information